GLOBAL RESEARCH SYNDICATE
No Result
View All Result
  • Login
  • Latest News
  • Consumer Research
  • Survey Research
  • Marketing Research
  • Industry Research
  • Data Collection
  • More
    • Data Analysis
    • Market Insights
  • Latest News
  • Consumer Research
  • Survey Research
  • Marketing Research
  • Industry Research
  • Data Collection
  • More
    • Data Analysis
    • Market Insights
No Result
View All Result
globalresearchsyndicate
No Result
View All Result
Home Data Collection

Data Of 25 Lakh Airtel Users In J&K Leaked After Failed Ransom Attempt

globalresearchsyndicate by globalresearchsyndicate
February 3, 2021
in Data Collection
0
Data Of 25 Lakh Airtel Users In J&K Leaked After Failed Ransom Attempt
0
SHARES
2
VIEWS
Share on FacebookShare on Twitter

While Airtel denies the data breach, some of the leaked phone numbers have been confirmed to be of active Airtel subscribers

The leaked data included names, phone numbers, DOB, gender and Aadhaar numbers, among other sensitive user details

The hacker released the data last month after failing to get a ransom from Airtel

In an alleged data breach, sensitive information of 25 lakh Airtel users was made publicly available on a website. While Airtel has denied the data breach, some of the leaked phone numbers have been confirmed to be of active Airtel subscribers

The data was allegedly leaked by a hacking group named Red Rabbit and included names, phone numbers, dates of birth, home addresses, Aadhaar and international mobile subscriber identity (IMSI) numbers. 

Notably, KYC requirements for Indian telcos make the collection of the above data from each user mandatory.

According to cybersecurity researcher Rajshekhar Rajaharia, who alerted Inc42 of this development, the hacker’s website, which contained the stolen data, went live sometime last month, after he had failed to get Airtel to pay a ransom for keeping news of the data breach under wraps. 

The hacker had claimed that the data of 25 lakh users was just a sample, and hence, all the affected users were from Jammu and Kashmir. The hacker claimed to have data of Airtel subscribers from several other Indian states and union territories and had threatened to make it public if the telco didn’t pay a ransom of around $3,500 bitcoins. That ransom didn’t materialise and the hacker subsequently posted the sample data online, also mentioning that the fuller database was up for sale. 

However, soon after Rajaharia shared information about the data leak on Twitter, the hacker’s website was pulled down. It is unclear if the website was pulled down voluntarily by the hacker or if it was the action of authorities. 

According to Rajaharia, the hacker claimed to have stolen the data by uploading a shellcode onto the victim’s server. Shellcode is a set of instructions that executes a command in software to take control of or exploit a compromised machine.

Airtel Denies Data Breach Despite Video Proof

In a statement, Airtel denied any data breach. 

“We confirm that there is no data breach at our end. In fact, the claims made by this group reveal glaring inaccuracies and a large proportion of the data records do not even belong to Airtel. We have already apprised the relevant authorities of the matter.”

Inc42 could confirm that at least some of the phone numbers in the leaked dataset belong to Airtel subscribers. We are also in possession of a proof of concept (PoC) video of the attack, which shows the hacker handpicking certain leaked phone numbers and verifying them to be Airtel subscribers through the telecom company’s SDR portal. 

A screenshot of the hacking group Red Rabbit’s website

Another short video reveals the emails exchanged between the hacking group, Red Rabbit and Airtel’s security team, starting December 31, 2020. In the chat, while the hacker talked about finalising a deal, Airtel’s security team responded by saying that they had apprised their seniors about the development, also asking the hacker to take down the website before the company confirmed the next steps.

A source told us that the hacking group had been trying to finalise a deal with Airtel for $3,000 since October 2019. Moreover, initial attempts were made by the group by posing as a journalist from Delhi, then as a police official. The source added that Airtel didn’t give in to the demand for a ransom, since the company wasn’t convinced about the authenticity of the data which the hacker had purportedly stolen. 

The source felt that the data could have been stolen from third parties, possibly even government agencies, with whom Airtel and other telcos are required to routinely share user data. However, cybersecurity expert and CEO of Netmonastery, a Mumbai-based network security company, Shomiron Das Gupta, talked about Airtel’s cybersecurity frailties. 

“Airtel’s cyber vulnerability is not new. Earlier in 2019 too their data vulnerability was brought to the attention of the company,” recounted Das Gupta. 

Airtel’s Dodgy Cybersecurity Track Record

In 2019, an independent security researcher had discovered a flaw in the Application Programming Interface (API) of Airtel’s mobile app, which could have exposed the data of 300 Mn users. Airtel had then claimed to have fixed the flaw immediately. 

“The possibility of the hack into Airtel’s systems cannot be ruled out. The hacker could have hacked the company’s server and created a back door entry,” he said.

It is worth mentioning that as per the Personal Data Protection Bill, 2019, set to be tabled in Parliament during the ongoing budget session, data fiduciaries are required to pay a penalty if they fail to comply with data processing obligations, directions issued by the Data Protection Authority, and cross-border data storage and transfer requirements.

The PDP bill mandates data fiduciaries — which collect, store and process users’ personal data for providing a service — to notify the DPA about a data breach that is likely to cause harm to customers, failing which, the fiduciary would have to pay a fine of up to INR 5 Cr or 2% of the worldwide turnover of the fiduciary, whichever is greater. 

In October last year, observant Twitter users had flagged a passage in Airtel’s privacy policy, which said that the company and its authorised third parties could collect store and process the following types of sensitive personal information from their users: genetic data, biometric data, racial or ethnic origin, political opinion, religious and philosophical beliefs, trade union membership, data concerning health, data concerning natural person’s sex life or sexual orientation, password, financial information (details of Bank account, credit card, debit card, or other payment instrument details) and physiological information.

Airtel had later posted a clarification and updated its privacy policy.

Related Posts

How Machine Learning has impacted Consumer Behaviour and Analysis
Consumer Research

How Machine Learning has impacted Consumer Behaviour and Analysis

January 4, 2024
Market Research The Ultimate Weapon for Business Success
Consumer Research

Market Research: The Ultimate Weapon for Business Success

June 22, 2023
Unveiling the Hidden Power of Market Research A Game Changer
Consumer Research

Unveiling the Hidden Power of Market Research: A Game Changer

June 2, 2023
7 Secrets of Market Research Gurus That Will Blow Your Mind
Consumer Research

7 Secrets of Market Research Gurus That Will Blow Your Mind

May 8, 2023
The Shocking Truth About Market Research Revealed!
Consumer Research

The Shocking Truth About Market Research: Revealed!

April 25, 2023
market research, primary research, secondary research, market research trends, market research news,
Consumer Research

Quantitative vs. Qualitative Research. How to choose the Right Research Method for Your Business Needs

March 14, 2023
Next Post
Online Plant Delivery Services Market 2021-2028 demand of next-gen booming with Amazon, Ugaoo, Bloomscape, Leaf & Clay, Modern Sprout – KSU

Online Plant Delivery Services Market 2021-2028 demand of next-gen booming with Amazon, Ugaoo, Bloomscape, Leaf & Clay, Modern Sprout – KSU

Categories

  • Consumer Research
  • Data Analysis
  • Data Collection
  • Industry Research
  • Latest News
  • Market Insights
  • Marketing Research
  • Survey Research
  • Uncategorized

Recent Posts

  • Ipsos Revolutionizes the Global Market Research Landscape
  • How Machine Learning has impacted Consumer Behaviour and Analysis
  • Market Research: The Ultimate Weapon for Business Success
  • Privacy Policy
  • Terms of Use
  • Antispam
  • DMCA

Copyright © 2024 Globalresearchsyndicate.com

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies to improve your experience. We'll assume you're ok with this, but you can opt-out if you wish. Cookie settingsACCEPT
Privacy & Cookies Policy

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these cookies, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may have an effect on your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
Non-necessary
Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.
SAVE & ACCEPT
No Result
View All Result
  • Latest News
  • Consumer Research
  • Survey Research
  • Marketing Research
  • Industry Research
  • Data Collection
  • More
    • Data Analysis
    • Market Insights

Copyright © 2024 Globalresearchsyndicate.com