41 comments

[ 45.0 ms ] story [ 946 ms ] thread
Data belonging to Indian Railways is up for sale on the dark web. A person with the username shadowhacker has posted the data of 30 million users on the portal for sale. The threat actor is also providing a sample database in plain text format. So, interested buyer can verify the data before the payment.
Forum?
str.join("raid","forums")
Raid isn't even a think anymore, breached just claims to be it's predecessor
Why not just write "raidforums"? (But no, that forum has been down for 8 months)
breached dot vc

And the people not wanting to mention the names amuses me, it’s like Voldemort or something ha!

For scammy sites direct Linking will just increase pagerank.
Breached.vc is not a scammy site.

Writing "raidforums" does not increase pagerank.

That's fucking great. Now, I am gonna be spammed even more.
Article says it's on the "dark web", but I was able to find the referenced forum post on the regular Web via Google in 5 seconds: https://breached.vc/Thread-Selling-INDIA-RAILWAYS-30-Million...

Incidentally, it's the same forum as the recent Twitter incident. https://news.ycombinator.com/item?id=34125843

Wow I'm shocked how cheap this is:

Prices, to keep this data anti public and affective only 5 copies will be sold

price per copy is 400$ [ negotiable ]

exclusive sale, only 1 person : 1500$

if you want to have the data + vulnerabilities we used to get into the database - 2000$

So either that's a good sum to their standard of living, or the data isn't all that personal and private in the first place.

The transit nerd in me kind of wants to buy it, not for maliciously tracking the customers, but to analyze the commuter and intercity travel patterns of 30m people.

Are there any potential consequences to buying data like this? I'd also be interested in buying/analyzing some of these data sets.
IANAL but, at the very least, you can't be charged with identity theft if you never actually use a stolen identity for anything.
IRCTC does not generally have much pii, except for adressess, phones, email. Aadhar can be linked but that on its own is not useful. Moreover a lot of accounts are burner accounts so the data is likely to be fake.
Does anyone buying an "exclusive" copy actually believe they're getting that?

The pricing is also interesting from another angle, if we take them at their word ("5 copies" vs "exclusive"): why accept 25% less overall? Assuming this is a cryptocurrency transaction, it surprises me the simplicity of dealing with a single buyer is worth that. Can anyone with more insight explain?

(comment deleted)
Possibly low demand for this because of the country, not a high income country to spam, scams or steal identities.
If @dang (I know @s don't work here) can update the link on the story, that would be great.
He won't see that. It is best to email hn@ycombinator dot com to reach Daniel.
“Dark web” is used more and more to refer to “sketchy” and not literally “onion-only site”.
[flagged]
You are publishing victim's personal information. How is this ok?
I'm repeating one line from a document linked in a top comment. This cat has left its bag long ago.
if i had the amount of money to throw around, i would love to encourage people like these making such disclosures.

hear me out. the public perception of hacking is "if its money then all police resources are behind you if you are lucky. if not then bad luck, police has more important work to do".

more of these hacks will happen, aadhar DB will be made public and websites will leak data. the public will learn the hard way that internet security is important as much as protecting your physical passport

This has been going on for more than 10 years, fairly frequently, and at increasing scale, and the public still hasn't learned. It requires something with severe impact for very many people (like hacking an entire bank or government) before the awareness will set in, I'm afraid. And even then I'm not convinced it'll happen and stick. Think climate change.
The public is utterly unable to effect any meaningful improvements that would reduce the occurence of this happening.
They can generate enough noise for politicians to start paying attention, though. The EU makes small steps from time to time. Enforcing laws remains a problem, though.
Ever heard or Equifax? After that beach I'm pretty confident the public will never care.
What can a regular user do to save their data from a breach like this? Aside from having strong unique passwords and changing as soon as they learn of a breach.

Seems like its all on the provider's side.

Only half-way realistic solution is to always provide false data about yourself unless there's a particular reason why they need your real address (such as delivering something). I guess that also requires reducing the amount of different sites you order from, or even preferentially turn to brick and mortar. If a site requires a CC for payment, you might get away with a false address if they don't verify it against the card. Otherwise you're going to have to avoid sites that don't allow you to use PayPal or more anonymous forms of payment.
When I was traveling with Renfe in Spain, they required the following information about me in order for me to be able to buy a ticket:

- Full name

- Phone number

- Passport number

Was it always like this in Spain, or did they introduce this after the train bombings in Madrid in 2004? https://en.wikipedia.org/wiki/2004_Madrid_train_bombings

Either way, it felt strange and unusual for me. In my country we can pay in cash and not enter any personal details unless we want to. In Spain, taking the train with Renfe is like taking an airplane to another country. They even have security gateways at the train station like the airports do.

india has a police station in every train station because it is considered "critical infra".... same for delhi metro (same would be probably true for all metro in India) which is guarded by CISF https://en.wikipedia.org/wiki/Central_Industrial_Security_Fo...

you need the same details as you mentioned to travel by trains in india but metro travel is still a cash only thankfully

buy the exclsuive copy of the data, or possibly pay the leakers to omit your information from sales
It almost like you shouldn't be tracking individuals in a public transport system.
seems to be a nosql dump, and further seems to be railyatri.in based on some investigation (threat actor did not clean up `.order_history[n].track_ref_deep_link` properly)
When are companies going to learn that holding identifiable user information like this is akin to holding toxic waste.