Premium

The invisible war for your Tatkal ticket: Railways blocks 17 billion bot attacks in a month

Discover how Aadhaar-based OTPs and a decoy system are finally defeating unauthorised agents and automated scripts.

AI generated image of Railways defence against Tatkal botsIn the last six months of 2025, IRCTC filtered out tens of billions of automated requests aimed at cornering the market for tickets. (Image generated using AI).

In a world where a Tatkal ticket can vanish faster than a summer breeze, the Indian Railways has revealed the staggering scale of the digital “arms race” happening behind your smartphone screen. Union Minister Ashwini Vaishnaw informed the Rajya Sabha recently that the national transporter’s booking system is not just a website; it is a digital fortress currently fending off billions of bot attacks every month to ensure genuine passengers get a seat, said the railways.

The sheer volume of malicious traffic targeting the Indian Railway Catering and Tourism Corporation (IRCTC) system is astonishing. In the last six months of 2025, the system filtered out tens of billions of automated requests aimed at cornering the market for tickets.

In October, the system reached its peak load of 24.04 billion requests. Of these, a massive 17 billion were identified as malicious bots and successfully blocked. This means that roughly 70.7 per cent of all traffic during this month was non-human.

In November, the following month, there was a slight dip but overall requests remained high at 20.07 billion. The security systems filtered out 14.03 billion bot requests, maintaining a high defence rate as nearly 70 per cent of attempts to access the site were automated scripts or hacking tools.

In September 2025, the platform handled 19.04 billion total requests. Out of these, 12.05 billion were flagged as bots. Despite the high volume of nearly 63.3 per cent bot traffic, the system’s multi-layered security controls ensured that genuine passengers could still access the booking services.

To combat this, the ministry has deployed “anti-bot” shields (like Akamai) and a Content Delivery Network (CDN) to ensure that while the bots are being blocked, your app doesn’t lag.

Aadhaar: The ultimate ‘speed bump’ for fraudsters

The most significant shift for regular travellers is the introduction of Aadhaar-based OTP verification for Tatkal bookings.

Story continues below this ad

By requiring a thumbprint or a mobile OTP linked to a unique ID, the system has effectively killed the “bulk account” strategy used by unauthorised agents. This “uniqueness constraint” ensures that one person equals one account, making it nearly impossible for hackers to use scripts to book dozens of tickets simultaneously.

Inside the cyber bunker

The Railways is not just playing defence; it is going on the offensive. Key security layers now include:

Honeypot (Madhu-Sanjal): In collaboration with CERT-In, the Railways has set up “decoy” systems to lure in hackers. This allows security teams to monitor their tactics in real time without exposing actual passenger data.

Deep dark web monitoring: Through RailTel, the government is now actively patrolling the underbelly of the internet to catch the sale of illegal booking software before it even hits the market.

Story continues below this ad

Massive deactivations: In a sweeping administrative crackdown, over 3.03 crore suspicious user IDs were deactivated in 2025 alone.

Physical fortification

While the digital battle rages in the cloud, the physical heart of the system is tucked away in a high-security data center in Chanakyapuri, New Delhi. This facility is ISO 27001 certified, monitored by 24/7 CCTV, and protected by “Data Centre Grade” firewalls capable of absorbing massive 30 Gbps DDoS attacks—the digital equivalent of a battering ram.

For the average traveller, these “invisible” wars mean more than just security; they mean availability. By blocking nearly 13,000 suspicious email domains and filtered out billions of bots, the system is finally tilting the scales back toward the common man, said the Railways.

As Minister Vaishnaw’s report suggests, the next time you successfully book a Tatkal ticket at 10.01 am, you might have a “Honeypot” or an Anti-bot filter to thank.

Story continues below this ad

Numbers

376- complaints lodged on the National Cyber Crime Portal pertaining to 3.99 lakh suspicious bookings.

12,819- suspicious email domains have been blocked in 2025.

Sweety Kumari is a seasoned journalist reporting from West Bengal for The Indian Express. With over a decade of experience in the media industry and eight years specifically with The Indian Express, she demonstrates considerable Expertise and Authority across a diverse range of critical beats. Experience & Authority Current Role: Journalist, The Indian Express, reporting from West Bengal. Extensive Tenure: Over 10 years of experience in the media industry, with a long association (8 years) with The Indian Express, contributing to a high level of Trustworthiness. Diverse Coverage: Covers crucial beats including Crime, Defence, Health, and Politics, alongside writing on trending topics. Investigative Focus: Possesses a keen eye for investigative and human-interest stories, demonstrating depth and skill in impactful journalism. Beat Versatility: Has honed her craft across diverse beats, including aviation and reporting on various incidents, ensuring well-rounded and comprehensive reportage. Career Start: Began her journalistic journey as an Entertainment and lifestyle journalist with a news portal in Kolkata, providing a foundational understanding of media landscape and audience engagement. Education Advanced Education: Holds a PG in Mass Communication from Jadavpur University, equipping her with advanced media theory and skills. Undergraduate Education: Holds an Honours degree in Journalism from Jaipuria College. Multilingual Skill: Her fluency in English, Hindi, Bengali, and Maithili enhances her reach and capability to connect with diverse sources and communities in the region, adding a layer of accessibility and authenticity to her reporting. Regional Roots: Originally from Bihar, she was brought up and educated in Kolkata (Kendriya Vidyalaya Salt Lake), giving her a deep, personal understanding of the cultural and political nuances of her reporting region. Sweety Kumari's combination of significant experience, specialization in key beats like Crime and Politics, and strong academic background makes her a trusted and authoritative contributor to The Indian Express. ... Read More

Stay updated with the latest - Click here to follow us on Instagram

Advertisement
Loading Recommendations...
Latest Comment
Post Comment
Read Comments