Chandigarh: A ransomware attack that disrupted the IT systems of Homi Bhabha Cancer Hospital Research Centre, New Chandigarh, has exposed serious gaps in cybersecurity preparedness at Tata Memorial Centre, with Comptroller and Auditor General (CAG) flagging the failure to conduct a root-cause analysis and implement measures to prevent a recurrence.The report, which contains the results of a compliance audit of the scientific and environmental ministries/departments of the Centre, their attached/subordinate offices, autonomous bodies and central public sector enterprises, pointed out that on Dec 2, 2024, an Interlock Ransomware incident was experienced by Homi Bhabha Cancer Hospital Research Centre. It was noticed that computer systems were not functioning and a pop-up message was appearing on their screens: “Data Security Crisis. Your Organisation’s most critical data is compromised, an infiltrated network, encrypted files and possessed highly sensitive information. Immediate action is required to avoid devastating consequences for your business”.The matter was escalated by the IT department on the same day to the local authorities and Computer and Information Security Advisory Group (CISAG) team. As of Dec 12, 2024, approximately 95% of IT services had been restored, while the remaining 5% was to be restored to fully operationalise the IT infrastructure of the hospital.The centre told CAG said the root-cause analysis had not been carried out and mitigation measures to prevent recurrence were yet to be taken. The audit noted that despite an advance alert by Indian Computer Emergency Response Team about ransomware malware attacks in Sept 2022, the actual cause behind the cyber-attack could not be identified due to non-initiation of root-cause analysis.Acknowledging the concerns raised, the centre stated in June 2025 that its internal response time and root-cause analysis protocols needed “improvement”. It said appropriate security measures, including multi-factor authentication, were being provisioned.The department noted the observations in Dec 2025 and stated that teams had been sensitised to update the latest patches as and when notified by CERT-In. It stated that a chief information security officer (CISO) and deputy CISO had been designated to ensure compliance with IT security requirements at each Tata Memorial Centre unit.CAG recommended a strong password management policy incorporating multi-factor authentication may be implemented to reduce the harm caused by phishing, credential leaks or unauthorised access attacks. It also recommended that the latest security patches may be installed on IT systems and regular monitoring of IT security processes may be undertaken to prevent cyber-attacks in compliance with the guidelines of Indian Computer Emergency Response Team and Union ministry of electronics and information technology.
