News Security Technology

Karnataka’s Kaveri 2.0 Portal Targeted In DDoS Attack, Disrupting Property Registrations

DDos attacks google cloudfare amazon
Following the disruption, K. A. Dayananda, Inspector General of Registrations and Commissioner of Stamps (IGR & CS), lodged a complaint with cybercrime authorities

The Kaveri 2.0 portal, Karnataka’s web-based system for streamlining property registrations, faced a crippling cyberattack in January, bringing registration services across the state to a near halt. Following an investigation, the Revenue and E-Governance Departments confirmed that the disruption was not due to a technical failure but a motivated Distributed Denial of Service (DDoS) attack—a malicious attempt to overload and crash the system.

Launched in 2023 to modernise land registration, Kaveri 2.0 plays a crucial role in document verification and transactions related to property. However, the recent attack highlights the growing vulnerability of critical digital services to cyber threats.

Kaveri 2.0 Resumes After Cyberattack

Following the disruption, K. A. Dayananda, Inspector General of Registrations and Commissioner of Stamps (IGR & CS), lodged a complaint with cybercrime authorities. The Cybercrime, Economic Offences, and Narcotics (CEN) police registered a case under the Information Technology Act, 2000, against unidentified attackers.

According to the First Information Report (FIR), Kaveri 2.0 had been experiencing performance issues since December 2024. After a detailed analysis with inputs from the Centre for Smart Governance (CSG), officials concluded that the problems were caused by a DDoS attack using automated bots and fake accounts.

How DDoS Attack Works

A Distributed Denial of Service (DDoS) attack overwhelms a targeted server, service, or network with an excessive flood of internet traffic, making it inaccessible to legitimate users. Unlike a traditional Denial of Service (DoS) attack, which originates from a single source, a DDoS attack is carried out through multiple compromised systems, forming a botnet.

These attacks do not directly steal data but can cause significant operational disruptions. In some cases, they serve as a distraction while more serious cyberattacks, such as data breaches, take place.

What Happened To Kaveri 2.0?

The attack on Kaveri 2.0 was methodically executed. Fake user accounts were created, and excessive database queries were generated, slowing down the system. Officials traced the attack to 62 email accounts linked to 14 different IP addresses, showing the distributed nature of the attack.

A particularly severe incident occurred in January 2025, when malicious users conducted an abnormally high number of encumbrance certificate (EC) searches—eight times the usual traffic volume. At one point, the system received 620,000 requests within just two hours, using random keywords to overload the portal. This surge effectively crippled Kaveri 2.0, drastically reducing the number of property registrations.

By February 1 and 4, the impact of the attack had severely disrupted operations. However, after intense mitigation efforts, the portal was successfully restored on February 5.

Growing Threat Of Cyberattacks

Cybersecurity experts warn that DDoS attacks are becoming more sophisticated and frequent, especially targeting government platforms and critical infrastructure. A recent study estimates that India could witness up to 17 trillion cyberattacks by 2047 if strong cybersecurity measures are not adopted.

DDoS attacks can also have political and economic motives. In August 2024, Elon Musk’s social media platform X (formerly Twitter) suffered a massive DDoS attack, causing significant delays and service disruptions. The attack occurred just before Musk’s scheduled conversation with then US presidential candidate Donald Trump, raising concerns about cyber threats targeting high-profile discussions.

Another prominent case occurred in 2015, when Microsoft-owned GitHub was targeted by a China-based botnet. The attack focused on GitHub projects providing tools to bypass Chinese state censorship. Malicious JavaScript code was injected into the browsers of users visiting Baidu, China’s largest search engine, allowing attackers to flood GitHub with traffic.

Preventing Future Attacks

To combat such cyber threats, organisations must adopt advanced traffic filtering systems to differentiate between legitimate and malicious users. Monitoring tools help detect unusual traffic spikes, allowing pre-emptive action. Rate-limiting measures can restrict the number of requests a user can make within a given time, preventing overload.

Bot detection technologies, such as CAPTCHA challenges and behavioural analysis, can prevent automated attacks. Regular security audits and multi-factor authentication further strengthen online platforms against unauthorised access.

Additionally, cybersecurity teams must collaborate with law enforcement and intelligence agencies to identify and mitigate attacks. Developing an incident response plan ensures that organisations are prepared to counter future threats effectively.

What Lies Ahead For Kaveri 2.0?

While Kaveri 2.0 has resumed operations, the cyberattack has served as a wake-up call for government agencies to prioritise cyber resilience. Ensuring the security of digital public services is essential in an era where cyber warfare and digital sabotage pose growing risks.

As cyber threats continue to evolve, proactive defence strategies, real-time monitoring, and public awareness will be crucial in safeguarding India’s digital infrastructure.

Leave a Reply

Your email address will not be published. Required fields are marked *