A data exposure linked to two AI-powered apps has revealed how loosely some platforms handle identity documents, personal images, and user trust.
The statement comes after the company was made party to an Indian lawsuit filed by Star Health last week, in which the insurer alleged that Cloudflare hosted the websites in question.
A simple Google search recently exposed websites leaking citizens' Aadhaar details, raising alarms about data privacy and security as India prepares to enforce its new Digital Personal Data Protection Act.
A hacker named ShopifyGUY claims to have leaked the data on dark web. The leaked data includes names, email IDs, phone numbers, and customer IDs of Boat customers.
The data sold was leaked from the Indian Council of Medical Research (ICMR).
According to a media report, a bad actor going by the handle, "Dnacookies" has demanded a sum of $5,000 (about Rs. 4.16 lakh) as ransom for the full dataset
Pwn0001 who is selling sensitive details of Indian citizens on a dark web website said that he has not hacked any database, but bought it from another dark web forum last year
The data includes personally identifiable information of US-based employees, and Sony says it will provide credit monitoring services.
The data included personal backups of Microsoft employees, personal data, passwords and private keys to internal Microsoft messages
Ransomware group BlackCat has claimed responsibility for the hack and claim to have 80GB of compressed data.
The accused persons were found selling more than 140 different categories of information, which include sensitive information such as details of defence personnel and the mobile numbers of citizens and NEET students, among others, Cyberabad Police Commissioner M Stephen Raveendra told reporters on Thursday.
Building a profile from user data to enable targeted phishing attacks on sensitive government accounts is plausible, however, there is no evidence that social media applications like TikTok has been used for this purpose.
The hackers urged Elon Musk and Twitter to buy the data exclusively from them to avoid paying $2.76 million in breach fines.
The Controller General of Defence Accounts said that Indian Computer Emergency Response Team (CERT-In) has issued a set of guidelines on how to avoid data breaches, which it urged employees to follow.
The database contains phone numbers from 84 different countries
Toyota said 296,019 email addresses and customer numbers of those using T-Connect, a telematics service that connects vehicles via a network, were potentially leaked.
Our specially curated package of the most interesting articles of the day will help you stay at the top of your game.
The person or group claiming the attack has offered to sell more than 23 terabytes of stolen data from the database, including names, addresses, birthplaces, national IDs, phone numbers and criminal case information, according to an anonymous post on an online cybercrime forum last week.
"It is false to assume that the bank is sharing any data with Chinese or any other foreign entities," Paytm CEO Vijay Shekhar Sharma said.
While assuring that the data is safe and secure, the government said that it has asked the Indian Computer Emergency Response Team to investigate the issue
The company BuyUCoin on the other hand has denied the breach and said it had conducted “routine testing with dummy data” in mid-2020.
The leaked data includes personally identifiable information of over 5,74,000 users, with over 2,92,000 people who made donations to the PM's National Relief Fund through PM Modi's personal website, Narendramodi.in.
Allowing the private sector access to select databases for commercial use can be fraught with risks
India needs to develop the capability to check hardware equipment sold by Chinese companies. This is because it is possible to create back doors in smartphones and other hardware equipment for surveillance.
The fact that company insiders were able to access the personal and financial details of the Paytm founder raises the question of whether the data harvested by private companies as a part of the e-KYC process stands compromised.