
A significant data breach at Hathway, a leading Indian Internet Service Provider (ISP), has allegedly exposed the personal details of millions of users, including KYC data. Though Hathway has yet to respond, analysis by Hackread.com suggests authenticity and potentially severe consequences for those affected.
The hacker, operating as ’dawnofdevil,’ revealed on Breach Forums that the breach exploited a security flaw in Hathway’s Laravel framework application, resulting in data exposure. The leaked database, comprising 12GB of data initially claimed to include 41 million customer records, contains personal information like names, email addresses, phone numbers, addresses, and Aadhaar card copies.
However, Hackread.com’s analysis identified around 35 million accounts, many duplicates or dummy accounts. After eliminating these, the actual impacted count reduces significantly to approximately 4 million accounts.
The hacker attempted to sell the data before resorting to its public release. This breach, which occurred in December 2023, involves customers’ and employees’ personal and financial details.
In an uncommon move, the hacker developed a dark web search engine for potential victims to verify if their information was exposed. However, the link to this tool hasn’t been shared publicly due to privacy concerns.
Hathway remains silent on the matter but cautions against phishing attempts purporting to be from the company, as this leak doesn’t contain passwords. Efforts to reach Hathway for comment are ongoing, and any updates will be reflected in subsequent reports. Users are advised to stay vigilant against potential scams targeting this breach.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543