Skip to content
Back to Blog
·6 min read·guides

Case Study: Chennai NBFC Ransomware Contained in 4 Hours

A Chennai-based NBFC discovered ransomware encrypting servers at 2:47 AM. By 6:51 AM, the attack was contained, evidence was preserved, and CERT-In Rule 3 notification was filed. Here's what happened.

Shouvik Mukherjee, Founder of Bachao.AI

Shouvik Mukherjee

Founder & CEO, Bachao.AI

Get Your Free VAPT Scan

What this means for your business

Indian SMBs without documented security controls face 3× higher breach costs (IBM Cost of a Data Breach 2024). This guide helps you close that gap.

2:47 AM — the page

A Chennai-based NBFC (we'll call them "LoanCo") had Bachao.AI on a retainer for 8 months when the incident page came through. Their CTO called the IR hotline at 2:51 AM: "Three of our application servers are showing ransom notes."

Bachao.AI's named incident commander was on the call by 2:53 AM. War-room Slack channel opened by 2:57 AM.

LoanCo's profile:

    1. 380 employees, 60,000 active borrowers
    2. AWS-hosted core lending platform
    3. 24/7 operations (collections, customer service, disbursements)
    4. RBI-regulated, CERT-In notification obligations applicable
    5. 8-month Bachao.AI IR retainer in place

3:00 AM — Initial assessment

Joint call with LoanCo CTO + Bachao IR commander:

    1. 3 application servers showing ransom notes (LockBit variant per the note format)
    2. Production database not yet affected (separate VPC, different credentials)
    3. Backups untouched (separate AWS account, S3 with object lock)
    4. Borrower-facing app showing 50% error rate (the encrypted servers were API consumers)
Decision (3:08 AM): contain immediately, do NOT pay ransom, do NOT power off (preserve evidence).

3:08 – 3:45 AM — Containment

Bachao.AI walked LoanCo's DevOps lead through:

    1. Network ACL change isolating the 3 encrypted servers from rest of infrastructure
    2. IAM credential rotation for the affected service accounts (15 keys rotated)
    3. Production database read-only mode (precautionary, given uncertainty about lateral movement)
    4. Borrower-facing app failover to backup region (~12 minutes of full-app downtime; degraded mode for 27 minutes)
By 3:45 AM, the attack was contained. The borrower-facing app was operational again.

Know your vulnerabilities before attackers do

Run a free VAPT scan — takes 5 minutes, no signup required.

Book Your Free Scan

3:45 – 5:00 AM — Evidence preservation + initial forensics

Bachao.AI forensic team:

    1. EBS snapshots of all 3 affected servers preserved
    2. CloudTrail logs for last 30 days exported to a secure analysis environment
    3. Memory dumps of the affected servers captured before any reboot
    4. Initial timeline reconstruction began
Findings by 5:00 AM:
    1. Initial access: a forgotten Jenkins server with an outdated plugin (CVE-2024-23899) exposed to the internet. Adversary entered 11 hours before the encryption fire.
    2. Lateral movement: from Jenkins → service account → 3 application servers. No further lateral movement.
    3. Data exfiltration: 8 GB transferred to an external IP over 3 hours. Content not yet determined.

5:00 – 6:51 AM — Regulatory notification

By 5:30 AM, the CERT-In notification was drafted. Submitted at 6:51 AM (4 hours 4 minutes after the page, well within the 6-hour requirement).

Parallel: RBI master direction on cyber incidents requires reporting via the bank's nodal officer; LoanCo's compliance head was briefed and ready to file the RBI notification by morning IST.

6:51 AM — End of acute phase

What was achieved in the first 4 hours:

    1. Attack contained
    2. No ransom paid
    3. No customer data lost (production DB never touched)
    4. ~39 minutes total customer-impacting downtime
    5. Evidence preserved for criminal investigation
    6. CERT-In Rule 3 notification filed inside 4 hours
    7. Communication plan ready for board + customers

Day 1–14 — Investigation and remediation

Day 1–3: Forensic analysis confirmed:

    1. The 8 GB exfiltrated was internal application code + 2 contractor laptops' staging data. No production borrower data.
    2. Adversary had been inside the Jenkins server for 11 days before encrypting (long dwell time used for reconnaissance)
    3. Persistence mechanism: a cron entry on the Jenkins server (now removed)
Day 3–7: Remediation:
    1. Jenkins server decommissioned (moved CI/CD to GitHub Actions)
    2. All Jenkins-issued tokens rotated
    3. New WAF rules deployed for CI/CD endpoints
    4. EDR coverage extended to legacy infrastructure (which Jenkins had been excluded from)
    5. DPB India notification filed precautionary (no personal data confirmed exfiltrated, but legal opted for transparency)
Day 7–14: Lessons learned:
    1. Post-incident review with LoanCo board
    2. Root cause document published internally
    3. Updated IR runbook reflecting actual response timing
    4. Communication to LoanCo's customer base (transparent disclosure)

What it cost

Line itemCost
Bachao.AI IR retainer (monthly)₹1.5L × 8 months = ₹12L
Incident-specific work (4-hour response + 14-day investigation)₹8L additional
LoanCo internal time (CTO, CISO, DevOps team, legal)~₹6L opportunity cost
Hardware/license: replacement CI/CD infrastructure~₹4L
Total Year-1 IR + incident₹30L
LoanCo's prior estimate for an emergency-only IR engagement (had they not been on retainer): ₹18L for the same incident + 4+ hour initial response delay.

What LoanCo's CTO said

"We had been paying the retainer for 8 months and never used it. Then for 4 hours one night, it was the most valuable money we'd ever spent. The difference between an emergency engagement and a retainer is the difference between explaining your AWS architecture at 3 AM and having a partner who already knows it. We renewed for 2 more years on the spot."

Pattern this engagement followed

This shape of incident is common at Indian NBFCs and fintechs:

  1. Legacy or forgotten infrastructure as the initial access vector
  2. Adversary dwell time of days/weeks before detonation
  3. Regulatory reporting compressed into the response window
  4. Operational continuity as critical as forensic accuracy
If your organisation needs the response capability before the incident:

Schedule the IR retainer scoping call →


Related: Cyber Incident Response Methodology India · CERT-In Reporting Workflow

Shouvik Mukherjee, Founder of Bachao.AI

Shouvik Mukherjee

Founder & CEO, Bachao.AI

Ex-enterprise architect turned cybersecurity founder. Built systems for Fortune 500s, now making enterprise-grade security accessible to every Indian business. Writes about threats targeting Indian SMBs, practical defenses, and the DPDP Act.

Connect on LinkedIn

Get cybersecurity insights for Indian SMBs

Weekly vulnerability alerts, DPDP compliance tips, and security guides. No spam — unsubscribe anytime.

We respect your privacy. Your email is never shared.

Find the gaps attackers use for initial access — before they do

Free automated scan — risk score in under 2 hours. No credit card required.

Get Your Free VAPT Scan
Find your vulnerabilitiesStart free scan →