India’s top online grocer BigBasket has suffered a potential data breach resulting in personal information of over 20 million customers being allegedly sold on the dark web. This incident follows a series of data breaches that have impacted Indian companies.
According to cybersecurity firm Cyble, which first made the details of the potential breach public, the alleged breach occurred on October 14. The firm said that it first detected the breach on October 30 and after validating the breach, it disclosed the breach to the Bigbasket management on November 1. The cybersecurity firm made the details of the breach public on November 7.
Cyble has claimed that personal information of as many as 20 million users such as full names, email IDs, password hashes (potentially hashed OTPs), pin, contact numbers (mobile and phone), full addresses, date of birth, location, and IP addresses of where users have logged in from have been put up for sale on the dark web for $40,000.
How to know if your data has been leaked on the dark web?
In a statement, the Bengaluru-based firm said it was evaluating the extent of the breach and authenticity of the claim in consultation with cybersecurity experts and was finding “immediate ways to contain it”. The company has also filed a complaint with the Cyber Crime Cell in Bengaluru. “The privacy and confidentiality of our customers is our priority and we do not store any financial data including credit card numbers etc., and are confident that this financial data is secure. The only customer data that we maintain are email ids, phone numbers, order details, and addresses so these are the details that could potentially have been accessed,” it said.
What have been the previous cases of data breaches in India?
If one only goes by the information released by Cyble, there have been six cases of cyber breaches in India in the last one month alone. These include incidents at snacks manufacturer Haldiram Snacks Pvt Ltd, Indian wedding planning website Wedmegood, Indian Prime Minister’s personal website narendramodi.in, online matrimonial service Bharat Matrimony and Indian Railways’ online ticketing portal IRCTC. In addition to this, late last month, pharmaceutical major Dr Reddy’s Laboratories witnessed a cyber attack. Cyble, had, in August also reported a data breach at e-commerce company Paytm Mall.