Breach report
Vimta Labs discloses cyber security incident affecting part of its IT systems
The Hyderabad testing and research lab told the stock exchanges on 21 August that it had detected a cyber incident, contained it and called in outside experts. It says operations were not affected.
What happened
Vimta Labs, a Hyderabad-based testing and contract research company listed on the NSE and BSE, told both exchanges on 21 August 2026 that it had recently detected a cyber security incident affecting a part of its IT infrastructure. The company said it began containment measures as soon as the incident was found and engaged external cyber security experts to assess the matter and support remediation.
The filing does not say when the intrusion began, how the attackers got in or what kind of attack it was. It does not mention ransomware, and we found no claim by a ransomware or extortion group naming Vimta as of 8 October 2026.
What was exposed
Vimta has not said whether any data was accessed or copied. The filing refers only to a part of its IT infrastructure and says a detailed assessment is under way with experts to find the root cause and take remedial action. The company provides testing and research services to drug makers and other businesses, but it has not said whether client, employee or study information was on the affected systems.
Confirmed vs. claimed
Confirmed by the company (exchange filing, 21 Aug 2026): a cyber security incident affected part of its IT infrastructure; containment measures were taken; outside experts were engaged; operations and customer delivery services stayed fully functional; no material impact on operations had been found so far.
Not known: the type of attack, when it started, whether data was taken and whether customers or staff are affected. The company said it would keep the exchanges updated. Its exchange filings up to 8 October 2026 contain no further update on the incident.
What to do if you are affected
- If you are a Vimta client or supplier, be extra careful with emails that ask you to change bank details for payments or to open attachments about pending reports or invoices. Confirm such requests by phone, using a number you already have.
- Ask your Vimta contact whether any of your data was on the affected systems and what is being done about it.
- Staff should watch for phishing emails that use internal details, and change any work password they have reused elsewhere.
- If you lose money to a fraud linked to this, call 1930 or report at cybercrime.gov.in.
Sources
More breaches in India
- RapiPay Fintech — 07 Oct 2026
- West Bengal State Data Centre — 22 Sep 2026
- Gujarat Mineral Development Corporation (GMDC) — 04 Sep 2026
- Cars24 — 04 Sep 2026
- Bajaj Life Insurance — 25 Aug 2026