The insightful articles, inspiring narrations and analytical perspectives presented by the Editorial Team, establish an alluring connect with the reader. My compliments and best wishes to SP Guide Publications.
"Over the past 60 years, the growth of SP Guide Publications has mirrored the rising stature of Indian Navy. Its well-researched and informative magazines on Defence and Aerospace sector have served to shape an educated opinion of our military personnel, policy makers and the public alike. I wish SP's Publication team continued success, fair winds and following seas in all future endeavour!"
Since, its inception in 1964, SP Guide Publications has consistently demonstrated commitment to high-quality journalism in the aerospace and defence sectors, earning a well-deserved reputation as Asia's largest media house in this domain. I wish SP Guide Publications continued success in its pursuit of excellence.
Espionage is rapidly evolving across cyber, space, maritime and human domains, making intelligence security, digital resilience and counter-surveillance critical national priorities for India.
![]() |
The Author is Former Director General of Information Systems and A Special Forces Veteran, Indian Army |
The world's top 10 intelligence agencies in 2026, ranked by global reach, technological capabilities, budget, and operational influence, in descending order are: CIA (USA), Mossad (Israel), MI6 (UK), MSS (China), FSB (Russia), R&AW (India), DGSE (France), BND (Germany), ISI (Pakistan), SVR (Russia). Japan recently overhauled its fragmented legacy intelligence framework, with the Diet approving: National Intelligence Council under Minister Sanae Takaichi; Tokyo-based National Intelligence Bureau (NIB) - Japan's first centralised foreign intelligence and operations agency since World War II.
Espionage is increasingly multi-domain, combining covert optical and audio surveillance with cyber tools, GPS tracking, OSINT, drones and counter-surveillance technologies.
Spying tools span hardware and software designed to covertly gather information, including hidden cameras (including pen or glasses cameras), listening devices (including parabolic mics and RF bugs) and GPS trackers. Software-based tools include stalker-ware and spyware used to intercept communications. Primary categories of tools used in espionage and surveillance include the following:
Examples of how China monitors India (https://www.sps-aviation.com/experts-speak/?id=1077&h=China-Sees-All) and how it has rigged its covert cyber-sabotage network (https://www.sps-aviation.com/experts-speak/?id=894&h=Chinas-Cyber-Spy-Sabotage-Network) to target India at critical moments has been covered in these columns earlier. China spies on India using a multi-layered espionage strategy that spans cyber warfare, maritime surveillance, embedded technology hardware, and human intelligence (HUMINT). Managed primarily by China's MSS and specialised military intelligence units, these operations focus heavily on tracking Indian military movements, compromising critical infrastructure, and mapping defence corridors.
China employs a layered intelligence strategy against India spanning cyber warfare, maritime surveillance, embedded technology hardware and HUMINT, with particular focus on military movements and critical infrastructure.
China relies heavily on state-sponsored Advanced Persistent Threat (APT) hacker groups to infiltrate Indian networks. Threat actors, such as the Warp Panda collective, focus on compromising virtual servers and cloud environments utilised by both public agencies and private sector organisations to quietly siphon data. Hackers target classified documents related to Indian missile defence systems, border security deployments, and high-level diplomatic communications. Beijing continuously deploys dual-use scientific research ships, such as the Da Yang Yihao, into the Indian Ocean Region (IOR). China's oceanographic research vessels map the seafloor to plot deep-water navigation corridors for Chinese submarines while tracking Indian naval fleets. China-manufactured electronics are embedded with the tech ecosystem; malicious communication modules and backdoors hardcoded into Chinese telecom components, router hardware, and green energy equipment - like solar inverters. For HUMINT, China uses a decentralised intelligence-gathering framework termed mosaic approach; cultivating contacts within civilian fields, focusing on policy analysts, defence think-tanks, aerospace scientists, and media personalities to subtly influence policy and extract strategic insights.
Pakistan's ISI (supported by China) employs a sophisticated, multi-layered approach combining cutting-edge space technology, digital warfare, and human assets for espionage against India. Pakistan's PRSC-EO3 satellite is placed into a specialised 38-degree inclined orbit to maximise high-frequency revisit rates directly over J&K and India. Hyperspectral and remote sensing Earth-observation satellites, like the PRSS series, allow Pakistan to bypass cloud cover, spot camouflage, and track day-and-night structural changes at Indian military installations. China's BeiDou military-grade navigation data access allows Pakistan to phase out GPS dependence for high-precision targeting and surveillance. ISI handlers create attractive fake profiles on platforms like Facebook, WhatsApp, and Instagram to target Indian defence personnel, scientists, and security forces. Operatives use malicious links sent via messaging apps to infect the devices of targeted individuals, allowing the ISI to clone phones, extract contacts, and track live locations. In border states like Punjab, India has uncovered instances where Pakistani handlers paid local individuals to install internet-enabled CCTV cameras at roadside shops along key national highways to stream live troop movements directly across the border. ISI espionage has shifted toward a decentralised, transactional hybrid model that targets everyday citizens rather than relying purely on highly trained deep-cover agents.
Pakistan's ISI is described as combining satellite-based surveillance, digital warfare and human assets, including social-media targeting, malicious links and the use of locally installed cameras for intelligence gathering.
With India's NavIC constellation rendered defunct due to neglect, adopting the Starlink system itself endangers national security, especially in critical situations. Starlink already covers Bangladesh and Starlink-compatible communication equipment has been recovered in India's northeast. American/Western mercenaries have been apprehended in Mizoram and close to India's border with Nepal.
In a recent security breach, 19,000 sensitive files related to the Kudankulam Nuclear Power Plant in Tamil Nadu (one of India's largest nuclear power plants) was compromised. The ransomware gang 'World Leaks' claimed on the dark web that these 14.3 gigabytes; of 8,58,000 Reliance Group (nuclear power plant contractor) files. NPCIL says the leak has no link to nuclear safety or security. Reuters has quoted Nickolas Roth, a senior director at the Nuclear Threat Initiative, which advises governments and benchmarks countries' preparedness on nuclear security, saying that the data breach could pose a serious risk to the safety of the plant.
IBM Security reports that India consistently ranks among the regions with high average total costs for a data breach, reaching roughly ₹22 crore per corporate breach. In 2025, India suffered the most data breaches, with 28.9 million accounts compromised, according to Surfshark. This Kudankulam data breach was the second time linked to malware tied to a North Korean hacker group found on the plant's administrative network after 2019. In a hack of the All-India Institute of Medical Sciences (AIIMS) in New Delhi in 2022, over 1.3 terabytes of data across five main servers crippled digital hospital services (including patient registration, billing, lab reports, and appointments) for nearly two weeks.
India needs stronger cyber resilience, including zero-trust architecture, micro-segmentation, secure backups, continuous threat detection, phishing-resistant MFA, staff training and effective implementation of the DPDP Act.
India's defensive strategies must focus on securing cloud infrastructure and mitigating primary attack vectors. A zero-trust architecture is required, including micro-segmentation to restrict lateral movement within networks. Overprivileged Identity and Access Management (IAM) must be eliminated. Cloud Security Posture Management (CSPM) tools must be adopted and enterprise backups secured. Extended Detection and Response (XDR) platforms need to be used to monitor endpoint telemetry continuously and block advanced credential-stealing trojans in real-time. In addition, robust Web Application Firewalls (WAF) should be implemented and phishing-resistant Multi-Factor Authentication (MFA) enforced.
Before India's Digital Personal Data Protection (DPDP) Act, having 2026-2027 compliance timeline, we only had a fragmented mix of general technology laws, sector-specific rules, and some judicial rulings. The crux lies in implementation of the DPDP Act. Majority regional organisations lack baseline security practices or are unaware of network intrusions. There is a need to run targeted phishing simulation campaigns, educate staff on deepfake voice cloning, and build a culture of active cyber hygiene. Continuous simulation training must include supply chains, vendor exploits, patching discovered vulnerabilities within strict timelines and prioritising internet-facing assets. Finally, the government must take urgent steps to track and counter threats to national security, including steps to regulate cybersecurity.