Data belonging to Indian Railways is up for sale on the dark web. A person with the username shadowhacker has posted the data of 30 million users on the portal for sale. The threat actor is also providing a sample database in plain text format. So, interested buyer can verify the data before the payment.
So either that's a good sum to their standard of living, or the data isn't all that personal and private in the first place.
The transit nerd in me kind of wants to buy it, not for maliciously tracking the customers, but to analyze the commuter and intercity travel patterns of 30m people.
IRCTC does not generally have much pii, except for adressess, phones, email. Aadhar can be linked but that on its own is not useful. Moreover a lot of accounts are burner accounts so the data is likely to be fake.
Does anyone buying an "exclusive" copy actually believe they're getting that?
The pricing is also interesting from another angle, if we take them at their word ("5 copies" vs "exclusive"): why accept 25% less overall? Assuming this is a cryptocurrency transaction, it surprises me the simplicity of dealing with a single buyer is worth that. Can anyone with more insight explain?
if i had the amount of money to throw around, i would love to encourage people like these making such disclosures.
hear me out. the public perception of hacking is "if its money then all police resources are behind you if you are lucky. if not then bad luck, police has more important work to do".
more of these hacks will happen, aadhar DB will be made public and websites will leak data. the public will learn the hard way that internet security is important as much as protecting your physical passport
This has been going on for more than 10 years, fairly frequently, and at increasing scale, and the public still hasn't learned. It requires something with severe impact for very many people (like hacking an entire bank or government) before the awareness will set in, I'm afraid. And even then I'm not convinced it'll happen and stick. Think climate change.
They can generate enough noise for politicians to start paying attention, though. The EU makes small steps from time to time. Enforcing laws remains a problem, though.
What can a regular user do to save their data from a breach like this? Aside from having strong unique passwords and changing as soon as they learn of a breach.
Only half-way realistic solution is to always provide false data about yourself unless there's a particular reason why they need your real address (such as delivering something). I guess that also requires reducing the amount of different sites you order from, or even preferentially turn to brick and mortar. If a site requires a CC for payment, you might get away with a false address if they don't verify it against the card. Otherwise you're going to have to avoid sites that don't allow you to use PayPal or more anonymous forms of payment.
Either way, it felt strange and unusual for me. In my country we can pay in cash and not enter any personal details unless we want to. In Spain, taking the train with Renfe is like taking an airplane to another country. They even have security gateways at the train station like the airports do.
india has a police station in every train station because it is considered "critical infra"....
same for delhi metro (same would be probably true for all metro in India) which is guarded by CISF https://en.wikipedia.org/wiki/Central_Industrial_Security_Fo...
you need the same details as you mentioned to travel by trains in india but metro travel is still a cash only thankfully
seems to be a nosql dump, and further seems to be railyatri.in based on some investigation (threat actor did not clean up `.order_history[n].track_ref_deep_link` properly)
The hacker claims data includes personal details such as name, email, phone number, and gender, as well as additional PII . The user also mentioned that there are multiple government email addresses present in the data. https://thecyberexpress.com/indian-railways-data-breach/
41 comments
[ 45.0 ms ] story [ 946 ms ] threadAnd the people not wanting to mention the names amuses me, it’s like Voldemort or something ha!
Writing "raidforums" does not increase pagerank.
Incidentally, it's the same forum as the recent Twitter incident. https://news.ycombinator.com/item?id=34125843
Prices, to keep this data anti public and affective only 5 copies will be sold
price per copy is 400$ [ negotiable ]
exclusive sale, only 1 person : 1500$
if you want to have the data + vulnerabilities we used to get into the database - 2000$
The transit nerd in me kind of wants to buy it, not for maliciously tracking the customers, but to analyze the commuter and intercity travel patterns of 30m people.
The pricing is also interesting from another angle, if we take them at their word ("5 copies" vs "exclusive"): why accept 25% less overall? Assuming this is a cryptocurrency transaction, it surprises me the simplicity of dealing with a single buyer is worth that. Can anyone with more insight explain?
hear me out. the public perception of hacking is "if its money then all police resources are behind you if you are lucky. if not then bad luck, police has more important work to do".
more of these hacks will happen, aadhar DB will be made public and websites will leak data. the public will learn the hard way that internet security is important as much as protecting your physical passport
Seems like its all on the provider's side.
- Full name
- Phone number
- Passport number
Was it always like this in Spain, or did they introduce this after the train bombings in Madrid in 2004? https://en.wikipedia.org/wiki/2004_Madrid_train_bombings
Either way, it felt strange and unusual for me. In my country we can pay in cash and not enter any personal details unless we want to. In Spain, taking the train with Renfe is like taking an airplane to another country. They even have security gateways at the train station like the airports do.
you need the same details as you mentioned to travel by trains in india but metro travel is still a cash only thankfully