77 lakh accounts blocked as Railways cracks down on bots
2.5 lakh Tatkal tickets booked everyday, 80% within 15 minutes of opening of window.
Written by Dheeraj Mishra
New Delhi | Updated: November 14, 2025 05:24 AM IST
3 min read
Whatsapp
twitter
Facebook
Reddit
Multi-layer security prevents automated software and suspicious IP addresses from accessing the systems.
Time-based steps on various booking pages, enhanced captcha verification and checks to ensure proper sequence of flow before reaching payment page are some of the measures taken by the Indian Railways over the past few months to prevent auto-filling of forms by hacking tools and curb fraud in tatkal ticket booking.
Officials said these measures, along with Aadhaar authentication in tatkal bookings, introduced in July 2025, have helped block over 77 lakh user IDs between February and October. On an average, 8.57 lakh bot accounts have been blocked during the period.
GVL Satya Kumar, the managing director of Centre for Railway Information Systems (CRIS), the technological wing of the Indian Railways, said the total number of attempts made by these bot accounts are much higher, intended to slow down the system and break the firewall to get the tickets booked in fraudulent manner.
“During the month of October, a total of 10.57 billion spurious attempts have been denied to access the e-ticketing system of Indian Railway. We have implemented a leading IT security solution with the e-ticketing system. This provides multi-layer security by preventing automated software and suspicious IP addresses from accessing the systems. We have set a threshold that if any attempt is being made to enter the data before 35 seconds, which is not possible manually, it will be immediately rejected,” said Kumar.
The IT system assigns each IP address a ‘reputation score’ based on its history and global usage behavior. IPs with poor scores or those linked to cyberattacks are automatically denied access, said the official. This approach also safeguards the network from Denial of Service (DoS) attempts designed to overload the servers.
The breakdown of server attacks shows that the majority are related to application vulnerabilities and attempts to book tickets before the 35-second threshold set by CRIS.
The Indian Railways has also made Aadhaar authentication mandatory for users booking Tatkal and Advance Reservation Period (ARP) tickets from July. Officials said over two crore users have already authenticated their IDs with Aadhaar, a figure that has doubled since June 2025.
Story continues below this ad
The newly launched RailOne App has been integrated with an App Shielding tool to prevent unauthorised intrusions. Along with this, the IRCTC’s anti-fraud team continuously analyses user IDs and deactivates suspicious accounts, said the official.
The data available with CRIS shows that on an average 2.5 lakh tatkal tickets are booked everyday; out of this one lakh tickets are for AC classes and 1.5 lakh tickets for non-AC classes.
The data further shows that almost 80% of tatkal tickets are booked within the first 15 minutes of the opening window, and that too for mostly 100 trains that face the highest demand.
Dheeraj Mishra is a Principal correspondent with The Indian Express, Business Bureau. He covers India’s two key ministries- Ministry of Railways and Ministry of Road Transport & Highways. He frequently uses the Right to Information (RTI) Act for his stories, which have resulted in many impactful reports. ... Read More