Back to the desk

News briefing

Bajaj Auto says ransomware attack led it to pause operations for a few days

Severity: HighIndiaIncident2026-0721-BA03 min readBy Vivek Kumar
Conceptual illustration: a padlock in a generic motorcycle assembly line. Text: BAJAJ AUTO RANSOMWARE.

AI-generated editorial illustration by CyberShitty. Not a photograph or a document from the organisations named.

The two- and three-wheeler maker reported a ransomware attack on itself and a tech subsidiary on the day it happened. It later told analysts it suspended operations for a few days as a precaution, denting quarterly output.

01 / What happened

Bajaj Auto told the BSE and NSE on 23 June 2026 that a ransomware attack had hit systems of the company and its wholly owned subsidiary Bajaj Auto Technology Limited (BATL). The filing, under Regulation 30 of SEBI's LODR Regulations, said the incident occurred at about 8am IST that day and had been reported to CERT-In under the Information Technology Act, 2000.

The company said its technical team, cyber-security experts and management responded promptly with precautionary steps to limit the impact, and that these had been successful based on the information available at the time. It called the disclosure a matter of good governance.

In an update filed on 26 June, Bajaj Auto said manufacturing, sales, service, dealer support, customer services and other key business functions were operating normally, and that the investigation was continuing.

The fullest account came on the company's first-quarter earnings call on 21 July, whose transcript was filed with the exchanges on 27 July. Management said the attack had been defended successfully but that, "exercising abundant caution, we suspended operations for a few days" to complete checks. Together with raw-material inflation and supply-chain and logistics disruption, it said, this cut availability by about 10% to 15%, more so in exports, high-end motorcycles and electric vehicles. The company reported quarterly volumes of 1.4 million units and said it had been looking at crossing 1.5 million.

02 / Why it matters

Bajaj Auto is one of India's largest vehicle makers and, The Record notes, the world's largest three-wheeler manufacturer. Its same-day filing is a clear example of a large listed Indian company reporting ransomware to the exchanges and to CERT-In as it unfolded.

Investors should read the filings and the earnings call side by side.

The two accounts differ in emphasis. The June update said key functions were operating normally; the July call said operations were paused for a few days as a precaution, with a measurable hit to output. A precautionary shutdown is often the price of containing ransomware, even when the attack is stopped.

03 / Who is exposed

Bajaj Auto has not said whether any data was stolen, which ransomware was used, or whether a ransom was demanded, and The Record reported that the company did not respond to its questions. No attacker has been named by the company or in the reporting reviewed for this article.

  • Customers and dealers: no confirmed exposure of personal or payment data.
  • Suppliers and business partners: no confirmed exposure, but disruption may have affected orders and dispatches during the pause.
  • BATL, the subsidiary focused on technology development, engineering and research, was among the affected systems.

04 / Confirmed vs. claimed

Confirmed (exchange filings and earnings call): a ransomware attack at about 8am IST on 23 June 2026 affecting Bajaj Auto and BATL; CERT-In notified; key functions operating normally by 26 June; operations suspended for a few days as a precaution; availability reduced by about 10% to 15% in the quarter, alongside other disruptions.

Unknown: whether data was exfiltrated, the ransomware family or group, any ransom demand, and the financial cost of the attack on its own. The Record said no link had been established with the separate Tata Electronics incident reported the same week.

05 / What to do now

  • Be cautious with messages claiming to come from Bajaj Auto or its dealers that ask for payments, OTPs or changes to bank details. Verify them using contact details from the company's official website.
  • Suppliers should confirm any change to payment instructions by calling a known contact before paying.
  • If you lose money, call the national cyber-fraud helpline 1930 immediately and file a complaint at cybercrime.gov.in; the faster a fraud is reported, the better the chance of stopping the money moving on.
  • Organisations: CERT-In's 2022 directions require ransomware and other malicious-code attacks to be reported within six hours, and ICT logs to be kept for a rolling 180 days. Keep offline, tested backups, separate subsidiary networks, and plan in advance who decides on a precautionary shutdown. Listed companies should also be ready to disclose under Regulation 30.

Source log / 2026-0721-BA

More from the archive