{"id":46933,"date":"2023-11-01T16:23:00","date_gmt":"2023-11-01T10:53:00","guid":{"rendered":"https:\/\/arcon.xyz\/risk-to-watch\/3-major-cyber-incidents-in-2023-and-lessons-learnt\/"},"modified":"2026-07-20T12:29:13","modified_gmt":"2026-07-20T06:59:13","slug":"3-major-cyber-incidents-in-2023-and-lessons-learnt","status":"publish","type":"risk-to-watch","link":"https:\/\/arcon.xyz\/staging01\/risk-to-watch\/3-major-cyber-incidents-in-2023-and-lessons-learnt\/","title":{"rendered":"3 Major Cyber Incidents in 2023 and Lessons Learnt"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\"><strong>Incident 1<\/strong><\/p>\n\n\n<p class=\"wp-block-paragraph\">The Reserve Bank of India (RBI) has slapped a whopping fine of INR 5.39 crore (approx. $ 648,000)  on one of the well-known Banks from India in October 2023 for not complying with the standard RBI guidelines related to KYC norms. Also, the organization failed to report incidents of cyber security breaches in time.<\/p>\n\n\n<p class=\"wp-block-paragraph\"><strong>Post-investigation find-outs<\/strong>: After thorough scrutiny headed by compliance investigation officials, it was found that there was not an adequate record of the end-user activities. The bank failed to produce enough evidence that they were continuously monitoring the IT tasks and transactions that can identify and raise red flags for suspicious IT sessions. There were no proper mechanisms in place for audit and reporting.\u00a0<\/p>\n\n\n<p class=\"wp-block-paragraph\"><strong>Incident 2<\/strong><\/p>\n\n\n<p class=\"wp-block-paragraph\">Another massive cyber incident surfaced in April 2023 in India where the police department of one of the southern states busted a gang of cybercrooks that compromised data of 66.9 crore individuals and put on sale. The data from 8 different cities, 24 states and 104 categories were illegally possessed by a malevolent that were operating from some other city of India.\u00a0<\/p>\n\n\n<p class=\"wp-block-paragraph\">The stolen data also included GST details of persons and companies, and the consumer\/customer data of major organizations such as road transport corporations of various states, major e-commerce portals, social media platforms and fintech companies.<\/p>\n\n\n<p class=\"wp-block-paragraph\"><strong>Post-investigation find-outs<\/strong>: According to the police officials, there was unauthorized access to the databases which included personal information. From the official database of various organizations, the bad actors compromised the personal details of millions of customers and users. The police did serve notices to over 11 different organizations, including banks, a social media giant, an IT services company, online insurance platform and others.<\/p>\n\n\n<p class=\"wp-block-paragraph\"><strong>Incident 3<\/strong><\/p>\n\n\n<p class=\"wp-block-paragraph\">A healthcare company in Mumbai, India faced a fraudulence of INR 2.25 crore (approx. $ 270,000) in October 2023, when an international hacker posing as a corporate communication manager, sent a phishing link to the company\u2019s owner. Instead of being cautious, the victim unfortunately clicked on the link and Rs 2.5 crore from the company&#8217;s cryptocurrency wallet was stolen. It has been observed that despite repeated warnings against clicking on unknown links, users fall prey to data breaches.\u00a0<\/p>\n\n\n<p class=\"wp-block-paragraph\"><strong>Post-Investigation find-outs<\/strong>: The owner or victim of the organization lodged a complaint to the cybercrime portal to inform about the offence. Police probing the case said that the complainant\u2019s wallet was hacked by a phishing link and the suspected scammer took help of advanced tools to execute the cyber-crime.<\/p>\n\n\n<p class=\"wp-block-paragraph\"><strong>Lessons learnt from the above cyber incidents<\/strong><\/p>\n\n\n<p class=\"wp-block-paragraph\">All the victim organizations did not heed enough importance to the <a href=\"https:\/\/arconnet.com\/blog\/security-compliance-productivity\/\">compliance mandates<\/a> that jeopardized and exposed them to cybercrime. Regulatory bodies demand strong IT practices around password management, user authentication, and authorization as well as mechanisms to detect anomalous activities including audit and reporting to stay protected from constant IT threats. Regulatory bodies expect organizations to impart their workforce with adequate education on looming cyber risks and how to avoid those risks.\u00a0<\/p>\n\n\n<p class=\"wp-block-paragraph\">Their primary and larger objective is to ensure that government and business organizations maintain data integrity, data privacy and data confidentiality.<\/p>\n\n\n<p class=\"wp-block-paragraph\">Today data is widely distributed in hybrid ecosystems and co-exists on on-premises data centers, multiple cloud platforms and in managed service environments. This evolving IT infrastructure has put data at grave risk from compromised insiders, suspicious third parties and organized cyber criminals. In the above incidents this is exactly what went wrong. Typically, inadequate IT security measures or half-baked policies play the spoilsport.\u00a0<\/p>\n\n\n<p class=\"wp-block-paragraph\"><strong>What went wrong in the above incidents?<\/strong><\/p>\n\n\n<p class=\"wp-block-paragraph\"><strong>Incident 1<\/strong>: The RBI (Reserve Bank of India) has provided guidelines on \u201cCyber Security Framework\u201d circular in 2016 where banks are asked to remain audit ready with the help of advanced real-time threat detection. The regular and automated reports generated on end-user activities helps the banks to detect and identify any kind of anomalies happening in the IT infrastructure. In a nutshell, the RBI demands a strong Identity and Access Management framework, had the organization implemented the RBI guidelines, they could have averted the IT incident.<\/p>\n\n\n<p class=\"wp-block-paragraph\"><strong>Incident 2: <\/strong>Prevention of unauthorized access is one of the top and dominant requirements mandated by most regulatory bodies and IT standards. This incident shows all the 11 organizations should have had stringent mechanisms to detect and identify unauthorized access or any anomalous activities in their IT infrastructure. Protecting citizens\u2019 data in an increasingly digitized world is getting challenging every day. And the new DPDP act is a step towards the right direction.<\/p>\n\n\n<p class=\"wp-block-paragraph\">The new DPDP (Digital Personal Data Protection) Act announced by the Government of India recently emphasizes on \u201cstrong protection\u201d of personal data irrespective of industry and organization size. It takes an integrated approach towards data protection without differentiating between how sensitive the personal data is \u2013 hence, safeguarding all data at the same level. Once the act is applicable to Indian organizations, the country will witness lesser number of similar incidents in the coming days for sure.<\/p>\n\n\n<p class=\"wp-block-paragraph\"><strong>Incident 3<\/strong>: The global compliance standard HIPAA (Health Insurance Portability and Accountability Act) mandates the healthcare industry to build a centralized policy framework so that they can enforce data security measures, stringent access control mechanisms and audit trails. It also demands security threat alerts and risk analytics to prevent anything anomalous. Had the organization been abiding by the policy standards, then there would not have been such disasters.<\/p>\n\n\n<p class=\"wp-block-paragraph\">Moreover, inadequate training as to the dos and don\u2019ts for cybersecurity also triggers such incidents. Amid increasing cases of phishing and malware attacks, users need to refrain from clicking links received from unexpected, unknown, and unsure sources. This minimizes the risks to a greater extent.<\/p>\n\n\n<p class=\"wp-block-paragraph\"><strong>How to minimize the risks of cybercrime?<\/strong><\/p>\n\n\n<p class=\"wp-block-paragraph\"><strong>Robust Identity and Access Management is a must\u00a0<\/strong><\/p>\n\n\n<p class=\"wp-block-paragraph\">Data is omnipresent and ever-growing. It is the biggest asset to ensure business expansion and continuity but is also vulnerable to breaches, espionage, or other security threats. It requires a robust access control framework, well-defined IT security policy and strong governance of identities that are frequently accessing the data assets for several reasons.\u00a0<\/p>\n\n\n<p class=\"wp-block-paragraph\">Enterprise-class <a href=\"https:\/\/arconnet.com\/whitepapers\/kuppingercole-whitepaper\/\">Identity Access Management (IAM)<\/a> solution remains a top-priority for organizations to ensure security control, identity lifecycle management and streamline overall access control frameworks. Regulatory compliance guidelines help organizations to build an unambiguous IT security policy. In fact, organizations can have effective IT security policies that manage, control, and monitor end-user accounts, conduct regular audits, and revoke elevated rights on time if any anomalous activity is found.\u00a0<\/p>\n\n\n<p class=\"wp-block-paragraph\">ARCON IAM solution in the given technology challenges enables an organization to take control of the management and monitoring of all the identities to comply with the access control requirements consistently with the regulatory standards.\u00a0<\/p>\n\n\n<ul class=\"wp-block-list\">\n<li>It helps the IT administrators to administer and govern digital identities when the number of end-users in an IT environment increases gradually.<\/li>\n\n\n<li>It can address the problem statements by automating the end-users\u2019 identity lifecycle management through provisioning and de-provisioning of end-users.<\/li>\n\n\n<li>It offers an intuitive workflow matrix and provides role and rule-based access to every critical system\/ application.<\/li>\n\n\n<li>It authenticates every access with multi-factor authentication and monitors the activities seamlessly after allowing access.<\/li>\n\n\n<li>It helps administrators to identify users who are deviating from the baseline policies and provides detailed analytics of end-user activities<\/li>\n<\/ul>\n\n\n<p class=\"wp-block-paragraph\"><strong>The Bottom-line:<\/strong><\/p>\n\n\n<p class=\"wp-block-paragraph\">Adhering to compliance mandates helps organizations to steadfastly build a proactive security framework.\u00a0<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Incident 1 The Reserve Bank of India (RBI) has slapped a whopping fine of INR 5.39 crore (approx. $ 648,000) on one of the well-known Banks from India in October 2023 for not complying with the standard RBI guidelines related to KYC norms. Also, the organization failed to report incidents of cyber security breaches in [&hellip;]<\/p>\n","protected":false},"author":40,"featured_media":47292,"parent":0,"menu_order":0,"template":"","meta":{"_acf_changed":false,"footnotes":""},"risk-categories":[],"class_list":["post-46933","risk-to-watch","type-risk-to-watch","status-publish","has-post-thumbnail","hentry"],"acf":{"blog_inner_page_contents":[{"acf_fc_layout":"hero_section","image":47292,"news_logo":"","publish_date":"","reading_time":"","heading":"","para":"","cta_text":"","cta_url":"","is_featured_post":false},{"acf_fc_layout":"page_contents","social_media_items":null,"sidebar_item_desktop":[{"id":"Incident 1","item_name":"Incident 1"},{"id":"Incident 2","item_name":"Incident 2"},{"id":"Incident 3","item_name":"Incident 3"},{"id":"Lessons learnt from the above cyber incidents","item_name":"Lessons learnt from the above cyber incidents"},{"id":"What went wrong in the above incidents?","item_name":"What went wrong in the above incidents?"},{"id":"How to minimize the risks of cybercrime?","item_name":"How to minimize the risks of cybercrime?"},{"id":"The Bottom-line:","item_name":"The Bottom-line:"}],"contents":[{"id":"Incident 1","title":"Incident 1","content":"<!-- wp:paragraph -->\r\n\r\nThe Reserve Bank of India (RBI) has slapped a whopping fine of INR 5.39 crore (approx. $ 648,000) on one of the well-known Banks from India in October 2023 for not complying with the standard RBI guidelines related to KYC norms. Also, the organization failed to report incidents of cyber security breaches in time.\r\n\r\n<!-- \/wp:paragraph --> <!-- wp:paragraph -->\r\n\r\n<strong>Post-investigation find-outs<\/strong>: After thorough scrutiny headed by compliance investigation officials, it was found that there was not an adequate record of the end-user activities. The bank failed to produce enough evidence that they were continuously monitoring the IT tasks and transactions that can identify and raise red flags for suspicious IT sessions. There were no proper mechanisms in place for audit and reporting.\r\n\r\n<!-- \/wp:paragraph -->"},{"id":"Incident 2","title":"Incident 2","content":"<!-- wp:paragraph -->\r\n\r\nAnother massive cyber incident surfaced in April 2023 in India where the police department of one of the southern states busted a gang of cybercrooks that compromised data of 66.9 crore individuals and put on sale. The data from 8 different cities, 24 states and 104 categories were illegally possessed by a malevolent that were operating from some other city of India.\r\n\r\n<!-- \/wp:paragraph --> <!-- wp:paragraph -->\r\n\r\nThe stolen data also included GST details of persons and companies, and the consumer\/customer data of major organizations such as road transport corporations of various states, major e-commerce portals, social media platforms and fintech companies.\r\n\r\n<strong>Post-investigation find-outs<\/strong>: According to the police officials, there was unauthorized access to the databases which included personal information. From the official database of various organizations, the bad actors compromised the personal details of millions of customers and users. The police did serve notices to over 11 different organizations, including banks, a social media giant, an IT services company, online insurance platform and others.\r\n\r\n<!-- \/wp:paragraph -->"},{"id":"Incident 3","title":"Incident 3","content":"<!-- wp:paragraph -->\r\n\r\nA healthcare company in Mumbai, India faced a fraudulence of INR 2.25 crore (approx. $ 270,000) in October 2023, when an international hacker posing as a corporate communication manager, sent a phishing link to the company\u2019s owner. Instead of being cautious, the victim unfortunately clicked on the link and Rs 2.5 crore from the company's cryptocurrency wallet was stolen. It has been observed that despite repeated warnings against clicking on unknown links, users fall prey to data breaches.\r\n\r\n<!-- \/wp:paragraph --> <!-- wp:paragraph -->\r\n\r\n<strong>Post-Investigation find-outs<\/strong>: The owner or victim of the organization lodged a complaint to the cybercrime portal to inform about the offence. Police probing the case said that the complainant\u2019s wallet was hacked by a phishing link and the suspected scammer took help of advanced tools to execute the cyber-crime.\r\n\r\n<!-- \/wp:paragraph -->"},{"id":"Lessons learnt from the above cyber incidents","title":"Lessons learnt from the above cyber incidents","content":"<!-- wp:paragraph -->\r\n\r\nAll the victim organizations did not heed enough importance to the <a href=\"https:\/\/arconnet.com\/blog\/security-compliance-productivity\/\">compliance mandates<\/a> that jeopardized and exposed them to cybercrime. Regulatory bodies demand strong IT practices around password management, user authentication, and authorization as well as mechanisms to detect anomalous activities including audit and reporting to stay protected from constant IT threats. Regulatory bodies expect organizations to impart their workforce with adequate education on looming cyber risks and how to avoid those risks.\r\n\r\n<!-- \/wp:paragraph --> <!-- wp:paragraph -->\r\n\r\nTheir primary and larger objective is to ensure that government and business organizations maintain data integrity, data privacy and data confidentiality.\r\n\r\n<!-- \/wp:paragraph --> <!-- wp:paragraph -->\r\n\r\nToday data is widely distributed in hybrid ecosystems and co-exists on on-premises data centers, multiple cloud platforms and in managed service environments. This evolving IT infrastructure has put data at grave risk from compromised insiders, suspicious third parties and organized cyber criminals. In the above incidents this is exactly what went wrong. Typically, inadequate IT security measures or half-baked policies play the spoilsport.\r\n\r\n<!-- \/wp:paragraph -->"},{"id":"What went wrong in the above incidents?","title":"What went wrong in the above incidents?","content":"<!-- wp:paragraph -->\r\n\r\n<strong>Incident 1<\/strong>: The RBI (Reserve Bank of India) has provided guidelines on \u201cCyber Security Framework\u201d circular in 2016 where banks are asked to remain audit ready with the help of advanced real-time threat detection. The regular and automated reports generated on end-user activities helps the banks to detect and identify any kind of anomalies happening in the IT infrastructure. In a nutshell, the RBI demands a strong Identity and Access Management framework, had the organization implemented the RBI guidelines, they could have averted the IT incident.\r\n\r\n<!-- \/wp:paragraph --> <!-- wp:paragraph -->\r\n\r\n<strong>Incident 2: <\/strong>Prevention of unauthorized access is one of the top and dominant requirements mandated by most regulatory bodies and IT standards. This incident shows all the 11 organizations should have had stringent mechanisms to detect and identify unauthorized access or any anomalous activities in their IT infrastructure. Protecting citizens\u2019 data in an increasingly digitized world is getting challenging every day. And the new DPDP act is a step towards the right direction.\r\n\r\n<!-- \/wp:paragraph --> <!-- wp:paragraph -->\r\n\r\nThe new DPDP (Digital Personal Data Protection) Act announced by the Government of India recently emphasizes on \u201cstrong protection\u201d of personal data irrespective of industry and organization size. It takes an integrated approach towards data protection without differentiating between how sensitive the personal data is \u2013 hence, safeguarding all data at the same level. Once the act is applicable to Indian organizations, the country will witness lesser number of similar incidents in the coming days for sure.\r\n\r\n<!-- \/wp:paragraph --> <!-- wp:paragraph -->\r\n\r\n<strong>Incident 3<\/strong>: The global compliance standard HIPAA (Health Insurance Portability and Accountability Act) mandates the healthcare industry to build a centralized policy framework so that they can enforce data security measures, stringent access control mechanisms and audit trails. It also demands security threat alerts and risk analytics to prevent anything anomalous. Had the organization been abiding by the policy standards, then there would not have been such disasters.\r\n\r\n<!-- \/wp:paragraph --> <!-- wp:paragraph -->\r\n\r\nMoreover, inadequate training as to the dos and don\u2019ts for cybersecurity also triggers such incidents. Amid increasing cases of phishing and malware attacks, users need to refrain from clicking links received from unexpected, unknown, and unsure sources. This minimizes the risks to a greater extent.\r\n\r\n<!-- \/wp:list -->"},{"id":"How to minimize the risks of cybercrime?","title":"How to minimize the risks of cybercrime?","content":"<strong>Robust Identity and Access Management is a must\u00a0<\/strong>\r\n\r\n<!-- \/wp:paragraph --> <!-- wp:paragraph -->\r\n\r\nData is omnipresent and ever-growing. It is the biggest asset to ensure business expansion and continuity but is also vulnerable to breaches, espionage, or other security threats. It requires a robust access control framework, well-defined IT security policy and strong governance of identities that are frequently accessing the data assets for several reasons.\r\n\r\n<!-- \/wp:paragraph --> <!-- wp:paragraph -->\r\n\r\nEnterprise-class <a href=\"https:\/\/arconnet.com\/whitepapers\/kuppingercole-whitepaper\/\">Identity Access Management (IAM)<\/a> solution remains a top-priority for organizations to ensure security control, identity lifecycle management and streamline overall access control frameworks. Regulatory compliance guidelines help organizations to build an unambiguous IT security policy. In fact, organizations can have effective IT security policies that manage, control, and monitor end-user accounts, conduct regular audits, and revoke elevated rights on time if any anomalous activity is found.\r\n\r\n<!-- \/wp:paragraph --> <!-- wp:paragraph -->\r\n\r\nARCON IAM solution in the given technology challenges enables an organization to take control of the management and monitoring of all the identities to comply with the access control requirements consistently with the regulatory standards.\r\n\r\n<!-- \/wp:paragraph --> <!-- wp:list -->\r\n<ul class=\"wp-block-list\">\r\n \t<li style=\"list-style-type: none;\">\r\n<ul class=\"wp-block-list\"><!-- wp:list-item -->\r\n \t<li>It helps the IT administrators to administer and govern digital identities when the number of end-users in an IT environment increases gradually.<\/li>\r\n<\/ul>\r\n<\/li>\r\n<\/ul>\r\n<!-- \/wp:list-item --> <!-- wp:list-item -->\r\n<ul class=\"wp-block-list\">\r\n \t<li style=\"list-style-type: none;\">\r\n<ul class=\"wp-block-list\">\r\n \t<li>It can address the problem statements by automating the end-users\u2019 identity lifecycle management through provisioning and de-provisioning of end-users.<\/li>\r\n<\/ul>\r\n<\/li>\r\n<\/ul>\r\n<!-- \/wp:list-item --> <!-- wp:list-item -->\r\n<ul class=\"wp-block-list\">\r\n \t<li style=\"list-style-type: none;\">\r\n<ul class=\"wp-block-list\">\r\n \t<li>It offers an intuitive workflow matrix and provides role and rule-based access to every critical system\/ application.<\/li>\r\n<\/ul>\r\n<\/li>\r\n<\/ul>\r\n<!-- \/wp:list-item --> <!-- wp:list-item -->\r\n<ul class=\"wp-block-list\">\r\n \t<li style=\"list-style-type: none;\">\r\n<ul class=\"wp-block-list\">\r\n \t<li>It authenticates every access with multi-factor authentication and monitors the activities seamlessly after allowing access.<\/li>\r\n<\/ul>\r\n<\/li>\r\n<\/ul>\r\n<!-- \/wp:list-item --> <!-- wp:list-item -->\r\n<ul class=\"wp-block-list\">\r\n \t<li>It helps administrators to identify users who are deviating from the baseline policies and provides detailed analytics of end-user activities<\/li>\r\n<\/ul>"},{"id":"The Bottom-line:","title":"The Bottom-line:","content":"<!-- wp:paragraph -->\r\n\r\nAdhering to compliance mandates helps organizations to steadfastly build a proactive security framework.\r\n\r\n<!-- \/wp:paragraph -->"}],"form_shortcode":"","choose_asset_type":"files","links":"","files":"","pardot_redirect_url":"","video_link":""}]},"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.3 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>3 Major Cyber Incidents in 2023 and Lessons Learnt - ARCON<\/title>\n<meta name=\"robots\" content=\"noindex, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"3 Major Cyber Incidents in 2023 and Lessons Learnt - ARCON\" \/>\n<meta property=\"og:description\" content=\"Incident 1 The Reserve Bank of India (RBI) has slapped a whopping fine of INR 5.39 crore (approx. $ 648,000) on one of the well-known Banks from India in October 2023 for not complying with the standard RBI guidelines related to KYC norms. Also, the organization failed to report incidents of cyber security breaches in [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/arcon.xyz\/staging01\/risk-to-watch\/3-major-cyber-incidents-in-2023-and-lessons-learnt\/\" \/>\n<meta property=\"og:site_name\" content=\"ARCON\" \/>\n<meta property=\"article:modified_time\" content=\"2026-07-20T06:59:13+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/arcon.xyz\/staging01\/wp-content\/uploads\/2026\/02\/Non-Compliance-and-Risks-1024x455-1.webp\" \/>\n\t<meta property=\"og:image:width\" content=\"1024\" \/>\n\t<meta property=\"og:image:height\" content=\"455\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/webp\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"6 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/arcon.xyz\\\/staging01\\\/risk-to-watch\\\/3-major-cyber-incidents-in-2023-and-lessons-learnt\\\/\",\"url\":\"https:\\\/\\\/arcon.xyz\\\/staging01\\\/risk-to-watch\\\/3-major-cyber-incidents-in-2023-and-lessons-learnt\\\/\",\"name\":\"3 Major Cyber Incidents in 2023 and Lessons Learnt - ARCON\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/arcon.xyz\\\/staging01\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/arcon.xyz\\\/staging01\\\/risk-to-watch\\\/3-major-cyber-incidents-in-2023-and-lessons-learnt\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/arcon.xyz\\\/staging01\\\/risk-to-watch\\\/3-major-cyber-incidents-in-2023-and-lessons-learnt\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/arcon.xyz\\\/staging01\\\/wp-content\\\/uploads\\\/2026\\\/02\\\/Non-Compliance-and-Risks-1024x455-1.webp\",\"datePublished\":\"2023-11-01T10:53:00+00:00\",\"dateModified\":\"2026-07-20T06:59:13+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/arcon.xyz\\\/staging01\\\/risk-to-watch\\\/3-major-cyber-incidents-in-2023-and-lessons-learnt\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/arcon.xyz\\\/staging01\\\/risk-to-watch\\\/3-major-cyber-incidents-in-2023-and-lessons-learnt\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/arcon.xyz\\\/staging01\\\/risk-to-watch\\\/3-major-cyber-incidents-in-2023-and-lessons-learnt\\\/#primaryimage\",\"url\":\"https:\\\/\\\/arcon.xyz\\\/staging01\\\/wp-content\\\/uploads\\\/2026\\\/02\\\/Non-Compliance-and-Risks-1024x455-1.webp\",\"contentUrl\":\"https:\\\/\\\/arcon.xyz\\\/staging01\\\/wp-content\\\/uploads\\\/2026\\\/02\\\/Non-Compliance-and-Risks-1024x455-1.webp\",\"width\":1024,\"height\":455},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/arcon.xyz\\\/staging01\\\/risk-to-watch\\\/3-major-cyber-incidents-in-2023-and-lessons-learnt\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/arcon.xyz\\\/staging01\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Risk To Watch\",\"item\":\"https:\\\/\\\/arcon.xyz\\\/staging01\\\/risk-to-watch\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"3 Major Cyber Incidents in 2023 and Lessons Learnt\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/arcon.xyz\\\/staging01\\\/#website\",\"url\":\"https:\\\/\\\/arcon.xyz\\\/staging01\\\/\",\"name\":\"ARCON\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/arcon.xyz\\\/staging01\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"3 Major Cyber Incidents in 2023 and Lessons Learnt - ARCON","robots":{"index":"noindex","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"og_locale":"en_US","og_type":"article","og_title":"3 Major Cyber Incidents in 2023 and Lessons Learnt - ARCON","og_description":"Incident 1 The Reserve Bank of India (RBI) has slapped a whopping fine of INR 5.39 crore (approx. $ 648,000) on one of the well-known Banks from India in October 2023 for not complying with the standard RBI guidelines related to KYC norms. Also, the organization failed to report incidents of cyber security breaches in [&hellip;]","og_url":"https:\/\/arcon.xyz\/staging01\/risk-to-watch\/3-major-cyber-incidents-in-2023-and-lessons-learnt\/","og_site_name":"ARCON","article_modified_time":"2026-07-20T06:59:13+00:00","og_image":[{"width":1024,"height":455,"url":"https:\/\/arcon.xyz\/staging01\/wp-content\/uploads\/2026\/02\/Non-Compliance-and-Risks-1024x455-1.webp","type":"image\/webp"}],"twitter_card":"summary_large_image","twitter_misc":{"Est. reading time":"6 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/arcon.xyz\/staging01\/risk-to-watch\/3-major-cyber-incidents-in-2023-and-lessons-learnt\/","url":"https:\/\/arcon.xyz\/staging01\/risk-to-watch\/3-major-cyber-incidents-in-2023-and-lessons-learnt\/","name":"3 Major Cyber Incidents in 2023 and Lessons Learnt - ARCON","isPartOf":{"@id":"https:\/\/arcon.xyz\/staging01\/#website"},"primaryImageOfPage":{"@id":"https:\/\/arcon.xyz\/staging01\/risk-to-watch\/3-major-cyber-incidents-in-2023-and-lessons-learnt\/#primaryimage"},"image":{"@id":"https:\/\/arcon.xyz\/staging01\/risk-to-watch\/3-major-cyber-incidents-in-2023-and-lessons-learnt\/#primaryimage"},"thumbnailUrl":"https:\/\/arcon.xyz\/staging01\/wp-content\/uploads\/2026\/02\/Non-Compliance-and-Risks-1024x455-1.webp","datePublished":"2023-11-01T10:53:00+00:00","dateModified":"2026-07-20T06:59:13+00:00","breadcrumb":{"@id":"https:\/\/arcon.xyz\/staging01\/risk-to-watch\/3-major-cyber-incidents-in-2023-and-lessons-learnt\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/arcon.xyz\/staging01\/risk-to-watch\/3-major-cyber-incidents-in-2023-and-lessons-learnt\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/arcon.xyz\/staging01\/risk-to-watch\/3-major-cyber-incidents-in-2023-and-lessons-learnt\/#primaryimage","url":"https:\/\/arcon.xyz\/staging01\/wp-content\/uploads\/2026\/02\/Non-Compliance-and-Risks-1024x455-1.webp","contentUrl":"https:\/\/arcon.xyz\/staging01\/wp-content\/uploads\/2026\/02\/Non-Compliance-and-Risks-1024x455-1.webp","width":1024,"height":455},{"@type":"BreadcrumbList","@id":"https:\/\/arcon.xyz\/staging01\/risk-to-watch\/3-major-cyber-incidents-in-2023-and-lessons-learnt\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/arcon.xyz\/staging01\/"},{"@type":"ListItem","position":2,"name":"Risk To Watch","item":"https:\/\/arcon.xyz\/staging01\/risk-to-watch\/"},{"@type":"ListItem","position":3,"name":"3 Major Cyber Incidents in 2023 and Lessons Learnt"}]},{"@type":"WebSite","@id":"https:\/\/arcon.xyz\/staging01\/#website","url":"https:\/\/arcon.xyz\/staging01\/","name":"ARCON","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/arcon.xyz\/staging01\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"}]}},"_links":{"self":[{"href":"https:\/\/arcon.xyz\/staging01\/wp-json\/wp\/v2\/risk-to-watch\/46933","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/arcon.xyz\/staging01\/wp-json\/wp\/v2\/risk-to-watch"}],"about":[{"href":"https:\/\/arcon.xyz\/staging01\/wp-json\/wp\/v2\/types\/risk-to-watch"}],"author":[{"embeddable":true,"href":"https:\/\/arcon.xyz\/staging01\/wp-json\/wp\/v2\/users\/40"}],"version-history":[{"count":4,"href":"https:\/\/arcon.xyz\/staging01\/wp-json\/wp\/v2\/risk-to-watch\/46933\/revisions"}],"predecessor-version":[{"id":51315,"href":"https:\/\/arcon.xyz\/staging01\/wp-json\/wp\/v2\/risk-to-watch\/46933\/revisions\/51315"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/arcon.xyz\/staging01\/wp-json\/wp\/v2\/media\/47292"}],"wp:attachment":[{"href":"https:\/\/arcon.xyz\/staging01\/wp-json\/wp\/v2\/media?parent=46933"}],"wp:term":[{"taxonomy":"risk-categories","embeddable":true,"href":"https:\/\/arcon.xyz\/staging01\/wp-json\/wp\/v2\/risk-categories?post=46933"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}