What Was Leaked and Who Krybit Targets
In its Weekly Intelligence Report dated 1 October 2026, threat-intelligence firm CYFIRMA reported that the Krybit ransomware group had stolen and published data belonging to an Indian construction company. CYFIRMA described the victim as one of India's largest civil construction and contracting firms: incorporated in November 1979, headquartered in New Delhi, listed on the NSE, with EPC and real-estate operations. We are not naming the company, and the identity matters less than the pattern.
The published material, about 222.48 GB in total, reportedly includes:
- national ID cards, tax documents and passport-related documents
- salary and financial records
- invoices
- email correspondence and signatures
Krybit is not an opportunist that stumbled onto Indian construction. CYFIRMA's report of 4 September 2026 lists India, Thailand, France, Brazil and Taiwan among the group's primary target countries, and names Real Estate and Construction among its main industries. An earlier CYFIRMA note of 1 May 2026 describes Krybit as a double-extortion operation: it encrypts files (appending a .KRYBIT extension and dropping a RECOVER-README.txt ransom note) and also steals data, then publishes it if the victim does not pay.
For any Indian contractor, that combination is the point. Restoring from backups solves the encryption half of a double-extortion attack. It does nothing about 222 GB of employee identity documents and commercial correspondence sitting on a leak site.
Why Project-Based Contractors Are Soft Targets
Large EPC and civil contractors have a risk shape that suits ransomware crews. The weaknesses are structural, not a sign of careless IT teams.
Many sites, many networks
A contractor running 30 or 40 live projects operates 30 or 40 temporary offices: site containers with consumer-grade routers, shared laptops, remote access back to head office, and connectivity that is set up fast and torn down when the project closes. Each site is a network edge that head-office security teams see only partially. Sites are mobilised on tight timelines, and security hardening rarely sits on the mobilisation checklist next to the batching plant and labour camp.
Subcontractors, consultants and project owners in the same mailbox
EPC delivery depends on dozens of subcontractors, vendors, design consultants, project management consultants and the owner's engineers, all exchanging drawings, bills, measurement sheets and approvals by email and shared drives. Every one of those relationships is a credential that can be phished or reused. A contractor's email system is effectively an extranet for the whole project ecosystem.
Bid and execution work is also document-heavy. Tender packages, BOQs, rate analyses, bank guarantees, joint-venture agreements and HR onboarding files for a large site workforce all live as files. That is exactly what a data-theft operation wants: high volume, high sensitivity, and easy to exfiltrate in bulk. The leaked categories in this incident (ID cards, salary records, invoices, correspondence) map closely to that document trail.
The DPDP Act Exposure From Employee Data
The largest legal issue in a leak like this is personal data. National ID cards, tax documents, passport details and salary records of employees are personal data under the Digital Personal Data Protection Act, 2023, and the contractor is the data fiduciary for them.
The DPDP Act requires a data fiduciary to take reasonable security safeguards to prevent a personal data breach and to notify both the Data Protection Board of India and each affected data principal when a breach occurs. Timing matters here. The DPDP Rules, 2025 phase the Act in, and these substantive duties apply from 13 May 2027 (see our DPDP compliance timeline). Once they apply, failure to take reasonable security safeguards carries a penalty of up to INR 250 crore under the Act's schedule, and failure to notify the Board or affected individuals carries a separate penalty of up to INR 200 crore. A leak of this kind today is a preview of the exposure contractors will carry from that date, and the safeguards that will be tested then have to be built now.
Separately, the CERT-In directions of April 2022 require reportable cyber incidents to be reported to CERT-In within 6 hours of noticing them. Ransomware and data leaks fall within the reportable categories.
For a cyber policy, the relevant covers are regulatory defence and, where insurable by law, regulatory fines and penalties, plus notification costs, call-centre and credit or identity monitoring for affected individuals. More on how the Act interacts with insurance is in our DPDP Act and data privacy insurance guide.
Listed-Company Disclosure Under SEBI LODR
An NSE-listed contractor has a second disclosure track. Under the SEBI (Listing Obligations and Disclosure Requirements) Regulations, 2015, a listed entity must disclose material events to the stock exchanges, and the board must assess whether a cyber incident is material under Regulation 30. SEBI's 2023 amendments also added details of cybersecurity incidents or breaches, and loss of data or documents, to the quarterly corporate governance compliance report.
Disclosure has two consequences that matter for insurance. First, it puts the incident into the public domain, which accelerates claims and correspondence from employees, project owners and counterparties. Second, it creates a record against which shareholders and regulators can later test whether the company's statements about the incident and its controls were accurate.
That second point is where cyber and directors and officers liability meet. A securities claim alleging inadequate disclosure, or a regulatory investigation into board oversight of cyber risk, would normally fall to the D&O policy rather than the cyber policy. Contractors should check that the D&O wording does not carry a broad cyber exclusion that leaves this gap uncovered.
Confidentiality Exposure to Project Owners and Partners
Leaked invoices and email correspondence create exposure beyond employees. EPC contracts with public-sector owners, private developers and joint-venture partners routinely include confidentiality clauses covering drawings, technical specifications, pricing, and in some sectors (defence, power, metro rail, airports) security-sensitive design information.
If correspondence on a leak site contains an owner's drawings or a partner's pricing, the contractor faces:
- Claims for breach of contractual confidentiality from owners or JV partners.
- Third-party claims from counterparties whose own data (bank details, signatures, personal data of their staff) sat in the leaked mail.
- Commercial fallout in future tenders, including pre-qualification questions about cyber incidents and information security certification.
The third-party liability section of a cyber policy (often called privacy and network security liability) responds to claims arising from a failure to protect third-party data. It does not usually cover a pure breach-of-contract claim where the contractor has assumed liability beyond what it would owe at law. Contractual liability exclusions in cyber wordings vary widely, so a contractor that signs strict confidentiality indemnities should test those against its policy before renewal.
Signatures in leaked correspondence are a separate concern. They can be lifted to forge letters, invoices or payment instructions sent to the contractor's own vendors and clients. Social engineering and funds transfer fraud cover, sometimes sold as an extension to cyber and sometimes under a crime policy, is the relevant line here.
Business Interruption: Delay Is the Real Cost
For a contractor, the ransomware loss that hurts most is often not the data. It is the stall in project execution. If ERP, project management and document-control systems are encrypted, measurement sheets cannot be certified, running-account bills cannot be raised, procurement stops, and site teams lose access to current drawings. Cash flow slows exactly when the company is paying incident responders.
Delay then cascades into the contract. Liquidated damages for delay, extended site overheads, idle plant and labour, and the cost of acceleration to recover lost time can all follow a few weeks of system outage at the wrong project milestone.
What cyber BI actually pays
A cyber policy's business interruption section pays loss of income and increased cost of working caused by a network outage after a covered cyber event, subject to a waiting period (commonly 8 to 24 hours) and an indemnity period. For a contractor, the measurement of "income" is the hard part: revenue is recognised on project progress, so the claim has to show which billings and margins were delayed or lost because of the outage, not because of monsoon, approvals or material shortages.
A contractor's existing contractors all risks or erection all risks cover will not fill this gap. Those policies insure physical loss or damage to the works, and most carry cyber exclusions. See our guide to cyber business interruption cover for Indian corporates for how indemnity periods and waiting periods are set.
How to Structure Cyber Cover for an EPC Business
A contractor buying cyber insurance should build the programme around the losses this incident illustrates rather than buying a generic SME form.
- Incident response and forensics: pre-agreed breach counsel, forensic investigators and negotiation support available from hour one, given the 6-hour CERT-In clock.
- Data restoration and extortion: costs to rebuild systems and, subject to legality and sanctions screening, extortion payments. Our note on ransom payments and the law in India covers the constraints.
- Business interruption: an indemnity period long enough to cover recovery of billing cycles (90 days is often too short for a large contractor), with dependent business interruption for key IT and cloud providers.
- Privacy and network security liability: third-party claims from employees, owners, JV partners and vendors.
- Regulatory defence: DPDP Board proceedings and penalties where insurable.
- Social engineering and funds transfer fraud: an explicit sublimit, given leaked signatures and correspondence.
Limits and underwriting
Limit sizing should start from employee and worker headcount (notification and monitoring costs scale with records), the number of concurrent projects, and the daily billing run-rate. Our analysis of breach costs and cyber limit adequacy offers a method. Underwriters will ask about MFA on email and remote access, endpoint detection on site laptops, offline backups, privileged access controls, and how site networks connect to head office. Contractors that can evidence segmentation between sites and core ERP will see better terms and fewer sublimits.
Finally, cover should extend to project-specific entities. Large contractors deliver through SPVs and JVs, and the cyber policy's named-insured definition should capture them or the JV agreement should require partners to carry their own cover.
Practical Steps Before the Next Renewal
Contractors do not need to wait for an incident to act on this. A short programme of work over the next renewal cycle closes most of the gap:
- Map where personal data sits, including site onboarding files held by labour contractors, and purge records no longer needed.
- Enforce MFA on email, VPN and remote desktop access for every site and every subcontractor account that touches company systems.
- Segment site networks from ERP and document-control systems, and keep immutable offline backups of project data.
- Review EPC contract templates for confidentiality indemnities and cyber force majeure language, and align them with policy wordings.
- Run a tabletop exercise that includes the company secretary (for LODR disclosure), HR (for DPDP notification) and project heads (for delay management).
- Check that D&O, crime and cyber wordings fit together without overlapping exclusions.
The 222 GB leak is one incident, but CYFIRMA's tracking puts India and construction among Krybit's main targets. Contractors who treat cyber as a project risk, alongside site safety and delay, will be better placed both to prevent the next attack and to recover from it. For the wider construction risk picture, see our construction industry page and the companion post on contractor claims in EPC projects.