❌

Reading view

There are new articles available, click to refresh the page.

Shadowhacker Hit The Headlines with Indian Railways Data

Shadowhacker, the well-known hacker/hacker group, claims to be breached the Indian Railways Booking portal.

This time, Shadowhacker are selling 30 Million User Info and Invoices related to Indian Railways in a popular Underground Hackers forum.

Indian Railways Breach

However, the hacker did not disclose any Vulnerability or Source of the data but posted some sample data that contained Passenger's name, emails, phone numbers, train numbers, pnr etc.

The hacker claims there were two endpoints for data harvesting, another for invoices, train number, arrival time, email, phone, passenger gender, nationality, and all passenger information. The data also contains emails related to the Indian government ending with gov.in email extension.

After analysis of the Sample data, we are not sure this data is of that 2019 breach, but according to some reports, this breach seems fresh.

Still, There was no official confirmation of this breach by Indian Railways

The Hacker Claimed that the data was fromΒ RailYatri

Shadowhacker Selling NetPlus Indian Internet Service Provider Database

Shadowhacker is well known for carrying out cyber attacks on Indian Hospitals and many other Companies and Government entities worldwide.

Netplus Broadband is a subsidiary of Fastway Transmission Pvt Ltd and is an emerging independent ISPs in Punjab, offers high speed Internet through cable modem platform to residential, SME and corporate customers in all major cities and township of Urban Punjab. And through hotspot wireless broadband in rural Punjab.

Netplus Hacked


The Hackers claimed they had gained access to the Netplus database and owned the data belonging to the Netplus customers, selling the data for 200$ In a famous Underground hacker's forum.Β 

Hacker claims the data contains 150K records, with Name, Email, City, and Status of Account.

Conclusion

However, we did not verify this breach as the ISP is limited to some cities. Also, we did not expect any reply from the company if we reach out to them.

Hackers Selling Access To CoWin Portal in The Dark Web

CoWin Indian's digital platform seems to be in Hacker's hands. Hackers Selling Access To CoWin Portal in a popular Underground forum.Β 

CoWin


CoWin is a digital platform used by the Indian Government to support its mass vaccination program. The platform provides services such as online registration, appointment scheduling & vaccine coverage tracking. CoWin also facilitates healthcare service providers in managing vaccine stock and administering the vaccines to eligible citizens at approved sites.

On December 8, an unknown Hacker claimed to have hacked the CoWin Portal, gained access to the admin portal, and owned the database.Β 

The Hacker Claims he has access to 5K employee records and can edit and delete the records. They also posted some sample data and screenshots, which seem legitimate data.

The Breached data contains the Full Name, phone number, address and PIN code.Β 

CoWin Breach


Here are some of the photos posted on the Dark web forum

CoWin breach

Phone Numbers, Addresses are blurred for privacy reasons.

CoWin Hacked



Conclusion

Since the data is of Internal Employees of CoWin, we cannot verify that the breach is confirmed; and that the Hacker did not disclose any vulnerability yet, the breach seems real. We will update this article if we find additional information.

❌