❌

Reading view

There are new articles available, click to refresh the page.

Shadowhacker Hit The Headlines with Indian Railways Data

Shadowhacker, the well-known hacker/hacker group, claims to be breached the Indian Railways Booking portal.

This time, Shadowhacker are selling 30 Million User Info and Invoices related to Indian Railways in a popular Underground Hackers forum.

Indian Railways Breach

However, the hacker did not disclose any Vulnerability or Source of the data but posted some sample data that contained Passenger's name, emails, phone numbers, train numbers, pnr etc.

The hacker claims there were two endpoints for data harvesting, another for invoices, train number, arrival time, email, phone, passenger gender, nationality, and all passenger information. The data also contains emails related to the Indian government ending with gov.in email extension.

After analysis of the Sample data, we are not sure this data is of that 2019 breach, but according to some reports, this breach seems fresh.

Still, There was no official confirmation of this breach by Indian Railways

The Hacker Claimed that the data was fromΒ RailYatri

Hackers Selling Access To CoWin Portal in The Dark Web

CoWin Indian's digital platform seems to be in Hacker's hands. Hackers Selling Access To CoWin Portal in a popular Underground forum.Β 

CoWin


CoWin is a digital platform used by the Indian Government to support its mass vaccination program. The platform provides services such as online registration, appointment scheduling & vaccine coverage tracking. CoWin also facilitates healthcare service providers in managing vaccine stock and administering the vaccines to eligible citizens at approved sites.

On December 8, an unknown Hacker claimed to have hacked the CoWin Portal, gained access to the admin portal, and owned the database.Β 

The Hacker Claims he has access to 5K employee records and can edit and delete the records. They also posted some sample data and screenshots, which seem legitimate data.

The Breached data contains the Full Name, phone number, address and PIN code.Β 

CoWin Breach


Here are some of the photos posted on the Dark web forum

CoWin breach

Phone Numbers, Addresses are blurred for privacy reasons.

CoWin Hacked



Conclusion

Since the data is of Internal Employees of CoWin, we cannot verify that the breach is confirmed; and that the Hacker did not disclose any vulnerability yet, the breach seems real. We will update this article if we find additional information.

Mass Layoffs: The Dark Truth Media and Companies might be Hiding

It's about something other than Over hiring, Fake Experience or Lack of budget. Everyone wants to know the truth aboutΒ Why Companies Firing Employees.

Mass Layoffs

Β Image by Mohamed Hassan from PixabayΒ 

Big tech companies have good intelligence. We all know they have outstanding background checks and strict and well-planned Interviews. A fake experience guy won't be able to survive in those companies as easily, and no one would believe that the companies are in heavy loss.

When I had a career gap, even companies refused to offer internships to me, and I did not stop. I stepped into freelancing and roamed here and there on the freelancing platforms. Those platforms did not suit me best. It was a challenging situation for me during the Covid Lockdown.

Later, People offered me a good amount of money to solve their programming-related queries, let's call it "Job Support", and I started to work for them. Sometimes, I spent all my time working for them but later realised they were cheating their managers and Companies.

Even though the companies are aware of the employees (Including Interns) outsourcing their work, I don't have any problem with that, as my goal is to earn money in that problematic situation. Even employees of Big companies are already started giving job support to others.

Whatever the reason behind the layoffs, I would like to convey my views on that, as I gave Job support to many People, and I have good Knowledge of how fake experience Job Markets run in India and abroad. Being an Infosec guy, I also know how Hackers and Ransomware gangs operate.

Do you remember How Uber was hacked?

Of course, it was due to an employee of the company who shared the VPN login credentials with a bad guy. He scanned the internal networks of the company then the magic happened.

Due to the Increase in Cyber Attacks during the Covid Lockdown, every company tried to safeguard themselves by using secure VPN connections on their Infrastructure; an employee has to go through the VPN to access their network.

Why would someone share the credentials with others?

There are a few reasons behind this.

  • For Money
  • Outsource their work
  • Other reasons

For Money

Ransomware Operators are always in search of insiders from their targetted companies. They often pay a heavy amount to share their login details or blackmail those employees into gaining access to their internal systems.

For Outsource their work

Many unskilled guys join a company through the backdoor process or by luck. During remote work culture, They often used to outsource their work. Many APT groups promise to do their job in exchange for some money. At the same time, they steal their confidential data without the employee's notice.

These are the only reasons I know.

VPN is not the issue here. Companies should also understand the threats they will get if their confidential code falls into the wrong hands.

My Views

Though this blog post may hurt those who were skilled enough and fired, I don't think any medium-level company gonna do the mass firing; moreover, many employees did not have anything to do with their job.

My views are always experiential, as a Developer, I have worked for many people in the past, and as an Infosec guy, I know how APT operate.Β 

Some company's financial management has genuinely fallen, which is one of the reasons behind the mass layoffs.

Remember, Ther are always a shortage of Talent for IT companies,

Companies that are always in need of Talent.Β 

Stay motivated, Upskill yourself, and Good Luck.

India's New Data Protection Bill, All You Need To Know

As a Cyber Security Expert, I was concerned about the Data Protection Bill of India, and, Finally, The Ministry of Electronics and Information Technology moved a step ahead.

In this post, we will discuss how the bill is effectively helpful for individuals and how much pressure it may create for the IT industry in India.

Of course, I am not an expert on digital laws, but as an Ethical Hacker, I have spent my time in European Bug Bounty Platforms and the Underground Hacker's Market Places. I also have good knowledge of the countries that deal with data protection.

Previously many IT laws appeared with a bang and were withdrawn silently; however, this bill is heavily inspired by the EU GDPR. Still, not enough. It has to implement a lot.

Data Protection Bill


Digital Personal Data Protection Act, 2022.

We are not Going to explain each and every line of the Act, but a quick overview. If you want to explore, you can refer to meity.gov.in

OverviewΒ 

  • There will be a separate board for Data Protection by the Government of India. Called "Data Protection Board of India" for taking accountability for those who did not follow the Act
  • The Personal Data can be processed for lawful purposes only. That means a data firm may collect data and process it as long as it doesn't go against the law
  • Before asking for Personal data, the companies must tell the users why they collect data.
  • The Data Processors (Companies) must take strict security safeguards to prevent data breaches.
  • Companies should ensure they have the Data Protection Officer responsible for answering the Question of Data Protection.Β 
  • In Case of a Data Breach, the Companies (Data Processors,Β Every Data Fiduciary) have to report to the Board.
  • Companies should remove the personal data of their users if that is no longer necessary for their business purposes.
  • When Processing a child's data, companies should ensure they have gone throughΒ parental consent and ensure there will be no harm or targeted advertising.Β Β 
  • The Transfer of Personal data outside India has limitations. Still, it has exceptions for Claiming legal rights,Β  processing by the court, orΒ  In the interest of detection, prevention, investigation etc., by the Government.
  • There will be heavy penalties if any Company, Business doesn't follow this Data Protection Act.

Since this is a quick overview, There are many other terms and conditions that we did not mention, as our aim is to give an overview of the act,

My Views

As we know, there are over 76 crores (760 million) active internet users in India, and over the coming years, this is expected to reach 120 crores (1.2 billion). Govt is taking a good step to protect citizens' personal data.Β 
Some people don't even know how their data is sold, marketed, or used for fraud.

If we look broader side of the Internet, there are many underground marketplaces for Hackers, where they buy and sell people's personal data by hacking into companies, and of course, Indian Company data is being published for free as no one cares for Indian Companies, and they don't have enough budget for a Ransomware Attacks nor to Protect their Infrastructure, India's Data Protection act is relatively weak beforeΒ 

European Nations have strict data protection rules. We had seen how the internet was banged when the GDPR rules were introduced. There are strict rules regarding privacy, and companies have to pay heavy penalties if they get breached, whereas, in India, the Companies Bravely deny the data breaches.

In European countries, companies take cyber security seriously to protect their infrastructure and even encourage white hat hackers to hack into their Applications and reward them for their findings, whereas in India, the reported bugs take years to patch or never be fixed.Β 

There are many things that the Indian Government should look into. For suppose, when registering a new Domain name, European Companies hide the Whois info and protect the owner's privacy. In India, we have to pay extra fees to protect our privacy.

However, there are many factors to discuss, compare and make it much better. Some of my views sound like satire. For some, it might be interesting.

Let me know your thoughts in the comments section.

Hackers Posted 70GB of Files Related To Tata Power For Free

Tata Power, India's Largest power supply company, has faced a cyber attack this year. This story is about how the hackers gained access to the company and how far the story started

Tata power

On 24th October, In the HiveLeaks darknet blog, the Hive Ransomware group claimed that they had encrypted the files of Tata Power. Hive operators claimed that they had encrypted Tata Power on 3rd October,Β 

They did not get any ransom from the Tata Group, the negotiation failed, and the Data related to Tata Power was released for free.

The Data Contains, Personal details of its customers, Internal billing, Bank records, Contract Information and other sensitive information. Now the Data is being shared across various Underground hacking forums.

According to research by Microsoft, Attackers used the decades-old vulnerability inΒ The Boa web server, which has been discontinued since 2005. Boa web serverΒ is used for IoT devices, Security Cameras,Β  Management consoles etc

Microsoft researchers also claimed that half of the IPs are not detected as malicious; therefore, The IPs belong to compromised IoT devices and routers used to spread malware.

❌