City
Epaper

Govt's Swachh City platform hacked, data of 1.6 cr people at risk: Researchers

By IANS | Updated: September 28, 2022 18:10 IST

New Delhi, Sep 28 Cyber-security researchers on Wednesday revealed that hackers have compromised the swachh.city platform, an initiative ...

Open in App

New Delhi, Sep 28 Cyber-security researchers on Wednesday revealed that hackers have compromised the swachh.city platform, an initiative of the Swachh Bharat Mission in association with the Ministry of Housing and Urban Affairs, that could put "critical information" of nearly 1.6 crore (about 16 million) users at risk.

From the data sample that was disclosed by the threat actor to substantiate his claim on the Dark Web, researchers were able to assess registered email addresses, password hashes, registered phone numbers, transmitted OTP information, login IPs, individual user tokens, and browser fingerprint information of the affected users.

The threat intelligence team of AI-driven Singapore-headquartered CloudSEK said the breach of the Swachhata Platform is the handiwork of threat actor LeakBase.

The finding showed that critical information of approximately 16 million users could be ending up in the wrong hands.

"The adversary, going under the monikers of LeakBase, Chucky, Chuckies, and Sqlrip on underground forums has shared a database containing Personal Identifiable Information (PII) such as email addresses, hashed passwords, User IDs etc, that allegedly affects 16 million users of the swachh city platform," the researchers noted.

LeakBase often operates for financial gain and conducts sales on its marketplace forum on the Dark Web.

"The database of size 1.25 GB has been disclosed under the post and has been hosted on a popular file-hosting platform," informed the team.

LeakBase also offers access to admin panels and servers of most CMS (content management systems).

"As individuals whose personal details such as phone numbers and email addresses are advertised for sale, there is a strong possibility of it being used against them," said CloudSEKA.

This information can be harvested by threat actors to conduct phishing, in the form of fake breach notice emails from Swachh City, and social engineering to reveal more sensitive information.

It would equip malicious actors with details required to launch sophisticated ransomware attacks, exfiltrate data, and maintain persistence, warned researchers.

This information can also be aggregated to further be sold as leads on cybercrime forums.

"Implement a strong password policy and enable MFA (multi-factor authentication) across logins. Patch vulnerable and exploitable endpoints and monitor for anomalies in user accounts, which could indicate possible account takeovers," advised the researchers.

Disclaimer: This post has been auto-published from an agency feed without any modifications to the text and has not been reviewed by an editor

Tags: Axis BankSwachh bharat mission in associationNew DelhiMinistry Of Housing And Urban AffairsThe new delhi municipal councilDelhi south-westMinistry for housing and urban affairsMinistry of housing and urbanNew-delhiMinistry of urban affairsMinistry of urban development
Open in App

Related Stories

NationalNew Delhi Railway Station Sees ‘Stampede-Like’ Chaos Due to Train Delays (Watch)

NationalAmit Shah Reviews Delhi’s Law & Order Situation, Says Illegal Intruders Will Be Identified and Deported

NationalDelhi: Speaker Vijendra Gupta Responds To LoP Atishi’s Letter, Says, “Surprising That Opposition Is Not Aware Of Rules”

NationalSupreme Court Dismisses Plea on Delhi Railway Station Stampede, Questions Evidence of 200 Deaths

NationalDelhi Metro Update: DMRC to Operate Special Early Morning Services for New Delhi Marathon 2025 on Feb 23; Check Full Schedule

Technology Realted Stories

TechnologyTech Mahindra headcount drops by 1,757 in Q4

TechnologyCentre extends financial aid to indigenous indoor air purification solution

TechnologyIndia to soon launch safety assessment rating for trucks and heavy vehicles: Nitin Gadkari

TechnologyBroadband subscribers stand at 944.04 million in Feb, tele-density up: TRAI

TechnologyIndia achieves breakthrough in gene therapy for haemophilia: Minister