Industry Risk Profiles

222 GB Leaked From an NSE-Listed Indian EPC Contractor: Why Ransomware Groups Target Construction Firms

CYFIRMA reported that the Krybit ransomware group published about 222 GB of data from a large NSE-listed Indian EPC contractor. Here is why construction firms are targeted, what the leak means under DPDP and SEBI LODR, and how to structure cyber cover for an EPC business.

Sarvada Editorial TeamInsurance Intelligence
9 min read

Listen to this article

Audio version • 9 min read

ransomwareconstructionEPC contractorscyber insurancedata leak

Last reviewed: October 2026

What Was Leaked and Who Krybit Targets

In its Weekly Intelligence Report dated 1 October 2026, threat-intelligence firm CYFIRMA reported that the Krybit ransomware group had stolen and published data belonging to an Indian construction company. CYFIRMA described the victim as one of India's largest civil construction and contracting firms: incorporated in November 1979, headquartered in New Delhi, listed on the NSE, with EPC and real-estate operations. We are not naming the company, and the identity matters less than the pattern.

The published material, about 222.48 GB in total, reportedly includes:

  • national ID cards, tax documents and passport-related documents
  • salary and financial records
  • invoices
  • email correspondence and signatures

Krybit is not an opportunist that stumbled onto Indian construction. CYFIRMA's report of 4 September 2026 lists India, Thailand, France, Brazil and Taiwan among the group's primary target countries, and names Real Estate and Construction among its main industries. An earlier CYFIRMA note of 1 May 2026 describes Krybit as a double-extortion operation: it encrypts files (appending a .KRYBIT extension and dropping a RECOVER-README.txt ransom note) and also steals data, then publishes it if the victim does not pay.

For any Indian contractor, that combination is the point. Restoring from backups solves the encryption half of a double-extortion attack. It does nothing about 222 GB of employee identity documents and commercial correspondence sitting on a leak site.

Why Project-Based Contractors Are Soft Targets

Large EPC and civil contractors have a risk shape that suits ransomware crews. The weaknesses are structural, not a sign of careless IT teams.

Many sites, many networks

A contractor running 30 or 40 live projects operates 30 or 40 temporary offices: site containers with consumer-grade routers, shared laptops, remote access back to head office, and connectivity that is set up fast and torn down when the project closes. Each site is a network edge that head-office security teams see only partially. Sites are mobilised on tight timelines, and security hardening rarely sits on the mobilisation checklist next to the batching plant and labour camp.

Subcontractors, consultants and project owners in the same mailbox

EPC delivery depends on dozens of subcontractors, vendors, design consultants, project management consultants and the owner's engineers, all exchanging drawings, bills, measurement sheets and approvals by email and shared drives. Every one of those relationships is a credential that can be phished or reused. A contractor's email system is effectively an extranet for the whole project ecosystem.

Bid and execution work is also document-heavy. Tender packages, BOQs, rate analyses, bank guarantees, joint-venture agreements and HR onboarding files for a large site workforce all live as files. That is exactly what a data-theft operation wants: high volume, high sensitivity, and easy to exfiltrate in bulk. The leaked categories in this incident (ID cards, salary records, invoices, correspondence) map closely to that document trail.

The DPDP Act Exposure From Employee Data

The largest legal issue in a leak like this is personal data. National ID cards, tax documents, passport details and salary records of employees are personal data under the Digital Personal Data Protection Act, 2023, and the contractor is the data fiduciary for them.

The DPDP Act requires a data fiduciary to take reasonable security safeguards to prevent a personal data breach and to notify both the Data Protection Board of India and each affected data principal when a breach occurs. Timing matters here. The DPDP Rules, 2025 phase the Act in, and these substantive duties apply from 13 May 2027 (see our DPDP compliance timeline). Once they apply, failure to take reasonable security safeguards carries a penalty of up to INR 250 crore under the Act's schedule, and failure to notify the Board or affected individuals carries a separate penalty of up to INR 200 crore. A leak of this kind today is a preview of the exposure contractors will carry from that date, and the safeguards that will be tested then have to be built now.

Separately, the CERT-In directions of April 2022 require reportable cyber incidents to be reported to CERT-In within 6 hours of noticing them. Ransomware and data leaks fall within the reportable categories.

For a cyber policy, the relevant covers are regulatory defence and, where insurable by law, regulatory fines and penalties, plus notification costs, call-centre and credit or identity monitoring for affected individuals. More on how the Act interacts with insurance is in our DPDP Act and data privacy insurance guide.

Listed-Company Disclosure Under SEBI LODR

An NSE-listed contractor has a second disclosure track. Under the SEBI (Listing Obligations and Disclosure Requirements) Regulations, 2015, a listed entity must disclose material events to the stock exchanges, and the board must assess whether a cyber incident is material under Regulation 30. SEBI's 2023 amendments also added details of cybersecurity incidents or breaches, and loss of data or documents, to the quarterly corporate governance compliance report.

Disclosure has two consequences that matter for insurance. First, it puts the incident into the public domain, which accelerates claims and correspondence from employees, project owners and counterparties. Second, it creates a record against which shareholders and regulators can later test whether the company's statements about the incident and its controls were accurate.

That second point is where cyber and directors and officers liability meet. A securities claim alleging inadequate disclosure, or a regulatory investigation into board oversight of cyber risk, would normally fall to the D&O policy rather than the cyber policy. Contractors should check that the D&O wording does not carry a broad cyber exclusion that leaves this gap uncovered.

Confidentiality Exposure to Project Owners and Partners

Leaked invoices and email correspondence create exposure beyond employees. EPC contracts with public-sector owners, private developers and joint-venture partners routinely include confidentiality clauses covering drawings, technical specifications, pricing, and in some sectors (defence, power, metro rail, airports) security-sensitive design information.

If correspondence on a leak site contains an owner's drawings or a partner's pricing, the contractor faces:

  1. Claims for breach of contractual confidentiality from owners or JV partners.
  2. Third-party claims from counterparties whose own data (bank details, signatures, personal data of their staff) sat in the leaked mail.
  3. Commercial fallout in future tenders, including pre-qualification questions about cyber incidents and information security certification.

The third-party liability section of a cyber policy (often called privacy and network security liability) responds to claims arising from a failure to protect third-party data. It does not usually cover a pure breach-of-contract claim where the contractor has assumed liability beyond what it would owe at law. Contractual liability exclusions in cyber wordings vary widely, so a contractor that signs strict confidentiality indemnities should test those against its policy before renewal.

Signatures in leaked correspondence are a separate concern. They can be lifted to forge letters, invoices or payment instructions sent to the contractor's own vendors and clients. Social engineering and funds transfer fraud cover, sometimes sold as an extension to cyber and sometimes under a crime policy, is the relevant line here.

Business Interruption: Delay Is the Real Cost

For a contractor, the ransomware loss that hurts most is often not the data. It is the stall in project execution. If ERP, project management and document-control systems are encrypted, measurement sheets cannot be certified, running-account bills cannot be raised, procurement stops, and site teams lose access to current drawings. Cash flow slows exactly when the company is paying incident responders.

Delay then cascades into the contract. Liquidated damages for delay, extended site overheads, idle plant and labour, and the cost of acceleration to recover lost time can all follow a few weeks of system outage at the wrong project milestone.

What cyber BI actually pays

A cyber policy's business interruption section pays loss of income and increased cost of working caused by a network outage after a covered cyber event, subject to a waiting period (commonly 8 to 24 hours) and an indemnity period. For a contractor, the measurement of "income" is the hard part: revenue is recognised on project progress, so the claim has to show which billings and margins were delayed or lost because of the outage, not because of monsoon, approvals or material shortages.

A contractor's existing contractors all risks or erection all risks cover will not fill this gap. Those policies insure physical loss or damage to the works, and most carry cyber exclusions. See our guide to cyber business interruption cover for Indian corporates for how indemnity periods and waiting periods are set.

How to Structure Cyber Cover for an EPC Business

A contractor buying cyber insurance should build the programme around the losses this incident illustrates rather than buying a generic SME form.

  • Incident response and forensics: pre-agreed breach counsel, forensic investigators and negotiation support available from hour one, given the 6-hour CERT-In clock.
  • Data restoration and extortion: costs to rebuild systems and, subject to legality and sanctions screening, extortion payments. Our note on ransom payments and the law in India covers the constraints.
  • Business interruption: an indemnity period long enough to cover recovery of billing cycles (90 days is often too short for a large contractor), with dependent business interruption for key IT and cloud providers.
  • Privacy and network security liability: third-party claims from employees, owners, JV partners and vendors.
  • Regulatory defence: DPDP Board proceedings and penalties where insurable.
  • Social engineering and funds transfer fraud: an explicit sublimit, given leaked signatures and correspondence.

Limits and underwriting

Limit sizing should start from employee and worker headcount (notification and monitoring costs scale with records), the number of concurrent projects, and the daily billing run-rate. Our analysis of breach costs and cyber limit adequacy offers a method. Underwriters will ask about MFA on email and remote access, endpoint detection on site laptops, offline backups, privileged access controls, and how site networks connect to head office. Contractors that can evidence segmentation between sites and core ERP will see better terms and fewer sublimits.

Finally, cover should extend to project-specific entities. Large contractors deliver through SPVs and JVs, and the cyber policy's named-insured definition should capture them or the JV agreement should require partners to carry their own cover.

Practical Steps Before the Next Renewal

Contractors do not need to wait for an incident to act on this. A short programme of work over the next renewal cycle closes most of the gap:

  1. Map where personal data sits, including site onboarding files held by labour contractors, and purge records no longer needed.
  2. Enforce MFA on email, VPN and remote desktop access for every site and every subcontractor account that touches company systems.
  3. Segment site networks from ERP and document-control systems, and keep immutable offline backups of project data.
  4. Review EPC contract templates for confidentiality indemnities and cyber force majeure language, and align them with policy wordings.
  5. Run a tabletop exercise that includes the company secretary (for LODR disclosure), HR (for DPDP notification) and project heads (for delay management).
  6. Check that D&O, crime and cyber wordings fit together without overlapping exclusions.

The 222 GB leak is one incident, but CYFIRMA's tracking puts India and construction among Krybit's main targets. Contractors who treat cyber as a project risk, alongside site safety and delay, will be better placed both to prevent the next attack and to recover from it. For the wider construction risk picture, see our construction industry page and the companion post on contractor claims in EPC projects.

Frequently Asked Questions

Why do ransomware groups like Krybit target Indian construction and EPC companies?
CYFIRMA lists India and the real estate and construction sector among Krybit's main targets. Contractors run many temporary site networks, share systems with large numbers of subcontractors and consultants, and hold large volumes of sensitive documents such as bids, invoices and workforce ID records. That combination makes initial access easier and stolen data more valuable for extortion.
Does a contractors all risks policy cover a ransomware attack?
No. Contractors all risks and erection all risks policies insure physical loss or damage to the works and usually exclude cyber events. Data restoration, ransom negotiation, business interruption from system outages and third-party privacy claims need a standalone cyber policy.
Will cyber insurance pay liquidated damages if a ransomware attack delays a project?
Usually not directly, because liquidated damages are a contractual penalty and most cyber business interruption wordings exclude them. Cyber BI pays lost income and increased cost of working, which can fund acceleration to avoid delay. Contractors should also negotiate force majeure language in EPC contracts that names cyber incidents.
What must a contractor do after employee data is leaked?
The immediate duty is to report the incident to CERT-In within 6 hours under the April 2022 directions, and a listed contractor must also assess disclosure under SEBI LODR. The DPDP Act's duty to notify the Data Protection Board of India and each affected individual, following the process in the DPDP Rules, 2025, applies from 13 May 2027 under the Rules' phased timetable. Telling affected employees early is still sensible so they can guard against identity misuse. A cyber policy can fund breach counsel, notification costs and regulatory defence.

Related Glossary Terms

Related Insurance Types

Related Industries

Related Articles

Sarvada Intelligence

Ready to see Sarvada in action?

Explore the platform workflow or start a product conversation with our underwriting automation team.

Explore the platform