CYBERSECURITY BREACHES IN INDIA’S ONLINE GAMING ECOSYSTEM

CYBERSECURITY BREACHES IN INDIA’S ONLINE GAMING ECOSYSTEM

AUTHOR – MAITHLY JAIN* & ASHOK DOBHAL**

* LAW COLLEGE DEHRADUN, UTTARANCHAL UNIVERSITY, DEHRADUN, UTTARAKHAND, INDIA

** ASSISTANT PROFESSOR, LAW COLLEGE DEHRADUN, UTTARANCHAL UNIVERSITY, DEHRADUN, UTTARAKHAND, INDIA

BEST CITATION – MAITHLY JAIN & ASHOK DOBHAL, CYBERSECURITY BREACHES IN INDIA’S ONLINE GAMING ECOSYSTEM, INDIAN JOURNAL OF LEGAL REVIEW (IJLR), 6 (9) OF 2026, PG. 507-514, APIS – 3920 – 0001 & ISSN – 2583-2344.

Abstract

An exponential growth has occurred in the digital economy in India, making the online gaming segment one of the fastest-growing digital segments in the world. But it’s grown faster than the lagging security protocols and statutory mechanisms in the country and caused a vastly larger and vulnerable attack surface. This paper explores the structural vulnerabilities of the Indian online gaming ecosystem, including the use of weak identity verification systems (KYC), vulnerable Application Programming Interfaces (APIs) and insecure third-party external payment mechanisms, as the major opportunities for malicious attacks. India’s legal framework is rooted in the Information Technology (IT) Act 2000, and is rife with deep operational divisions in the statutes.[1] This study shows how the territorial approach of the old laws is not capable of countering automated and borderless digital threats like Remote Code Execution (RCE) and Distributed Denial-of-Service (DDoS) attacks through a critical legal analysis of them, namely Section 43A (negligent data protection standards), Section 66 (computer-related offenses), Section 79 (intermediary safe harbour immunity), and Section 85 (vicarious corporate liability). In addition, the paper identifies key systemic weaknesses, such as the fact that a lot of reports are still delayed after 72 hours, jurisdictional restrictions on jurisdiction over offshore servers, corporate implementation of safe harbour provisions and devastating capacity gaps in the local law enforcement cyber cells.[2]

The Indian courts have been filling a legislative void, especially due to a weak legislative framework. It charts a unique trajectory towards more aggressive judicial supervision as seen in the world-famous security audit decision in 2025 by the Delhi High Court, the enforcement of compliance by the Karnataka High Court and in individual cases by state consumer forums. It contends, however, that the less interventionist judicial response approach can never go far enough to prevent permanent, real-time exfiltration of data, and so will inevitably result in structural limits that expect Supreme Court cybersecurity directives.[3]

Lastly, the paper analyzes the paradigm shift in the world of online gaming, spurred by the two new sets of rules, namely, the Digital Personal Data Protection (DPDP) Rules, 2025 and the Promotion and Regulation of Online Gaming (PROG) Rules, 2026. This modern regime, led by the newly formed Online Gaming Authority of India, will have a new style of enforcement, kicking into the online arena, with the multi-crore fines being scaled and a strict distinction being made between banned online money games and online e-sports and social games. Finally, the study proposes a co-regulatory framework that will strike a balance between the need for innovation protections and an irrefutable user safety imperative and suggests embedding proactive, automated technical compliances into the very design of platforms to protect citizens’ privacy in the digital era.

Keywords: Privacy Rights, Data Privacy, Online Gaming, Cybersecurity Breaches, Information Technology Laws, Intermediary Liability, Digital Personal Data Protection Act, PROG Rules 2026, India


[1] N. Pandey & S. Tarun, Regulatory Progress and Challenges in India’s Booming Online Gaming Market, 2024 Online Gaming India 49, 49–61.

[2] S.T. Shrivastava, Cyber-Security and Data Privacy Challenges in Online Gaming: Analyzing the Cyber-Security Risks and Challenges Faced by Online Gaming Platforms in India, in Online Gaming in India 118, 118–25 (2024).

[3] V. Singhania & P. Talukdar, In Regulatory Purgatory: How Many Lives Left Before Mission Success for the Indian Gaming Industry?, in Online Gaming in India 27, 27–37 (2024).