Threat actors have published on the dark web the sensitive personal information of millions of Indian users of the train ticket booking platform RailYatri.
RailYatri, a popular Indian train ticket booking platform, suffered a massive data breach in December 2022 that exposed the over 31 million personal data records of its users. The data trove containing 12 GB of compromised information has now been published on a dark web forum named Breachforums, which is an alternative to the now-seized Raidforums.
A malicious actor who published the data trove said it includes personally identifiable information of RailYatri users like names, phone numbers, email addresses, genders, location of the user, and 37,000 invoices, among other things. This has put millions of individuals at risk of identity theft, phishing scams, and other cyber crimes.
Railyatri is yet to comment on how the threat actor infiltrated its network, what steps it has taken to avoid such incidents in the future, or if it intends to notify affected individuals.
Security researcher Anurag Sen, who discovered the breach in December, had identified similar cyber incidents affecting RailYatri in the past. For instance, he discovered in 2020 a misconfigured and unprotected Elasticsearch server owned by the company that could be accessed by anyone with an Internet connection.
After being informed by Sen, RailYatri disputed the ownership of the unprotected server and later said that it was “test data”. The server was secured only after the Indian Computer Emergency Response Team (CERT-In) intervened. During that time, the unprotected server contained around 37 million entries in total, including more than 700,000 internal production logs.
“Back in 2020, when I contacted Railyatri, they never reacted or reached out to me, but once I contacted Cert-In, the server got shut down. I have reported numerous data leaks in India; the main problem I observed is that these corporations are not receiving fines because India does not have a GDPR-like statute,” Anurag
explained.
Catering to over 24 million passengers daily, Indian Railways is considered one of the busiest transportation systems around the world. RailYatri was primarily designed for booking tickets, getting updates on train schedules, journey progress, offline timetables, checking seat availability, and offline GPS train status.
In December last year, India Federal Bank and its subsidiary, Fedfina, suffered a significant data breach that exposed the sensitive personal information of around 600,000 customers.
According to SafetyDetectives, a threat actor uploaded on a cyber criminal forum a database that contained the personally identifiable information (PII) of approximately 600,000 customers of Federal Bank and its subsidiary.
The database was found to contain approximately 122MB of data, totalling 637,000 data records. The solen details included 589,000 unique records such as customer IDs, full names, dates of birth, physical addresses, email addresses, phone numbers, age, gender, fathers’ name, spouses’ names (if applicable), PAN card numbers (Income tax department-related ID numbers), driver’s license number, passport numbers (if applicable), and voter IDs.