‏إظهار الرسائل ذات التسميات Darknet. إظهار كافة الرسائل
‏إظهار الرسائل ذات التسميات Darknet. إظهار كافة الرسائل

Details of 4+ Crore Indian TrueCaller Users Available on Darknet - Report

Details of over four crore Indian users of TrueCaller are now available for sale at just $1,000 on the Dark Web, as per Cyble Inc, a U.S -based cyber intelligence firm.

Truecaller however has denied the breach and according to a LiveMint report, the company has said that there has been no breach of the company’s database and all user information was secure.

The indentified cyber-criminal behind the data leak is posing by the name of 'TooGod' on the dark web. The low price suggests that the threat actor has some interest in gaining attention or expanding his customer base.

According to a company spokesperson's statement, "We were informed about a similar sale of data in May 2019. What they have here is likely the same dataset as before."

Truecaller is a mobile app that has features of caller-identification, call-blocking, and flagging spam numbners

According to a report by The Hindu, citing a study by cyber-intel firm Cyble -- the leaked data reveals that the details belong to citizens from all over the country, including from States like Maharashtra, Bihar, Andhra Pradesh, Delhi, Haryana, Madhya Pradesh, North East India, Odisha and Punjab, along with another folder titled ‘Unknown’. The details include phone numbers, names, genders, locations, emails ids and Facebook profile information.

Researchers from Cybel have identified a known player on the dark web offering details of a whopping 4.75 crore Indians for sale. Even more surprisingly, the entire packet, which would be regarded as a goldmine in terms of the sheer number of ways it can be misused, is being offered for a surprisingly low $1,000.

Cyble has indexed this information on AmiBreached.com -- Cyble’s data breach monitoring and notification platform. People who are concerned about their exposure can register on the website to ascertain their exposure,

Indian central and State cybercrime agencies have initiated investigations into the matter, taking into account the scope for the number of crimes that can be committed, including phishing rackets and identity thefts.

Stolen Data From Over 6,000 Indian Businesses Available On Darknet, Claims Quickheal

In a worrying piece of news coming in for the Indian companies, a forum on DarkNet is reportedly selling data stolen from over 6,000 Indian businesses that includes Internet Service Providers (ISPs), some of the key government organisations, banks and enterprises. The advertisement was recently spotted by global IT security firm Quick Heal's Enterprise Security brand Seqrite.

In a company statement, Seqrite shared further details about the advertisement they discovered along with its partner seQtree InfoServices. According to the statement, the mastermind hacker behind the advertisement is demanding 15 Bitcoins (nearly INR 42 lakh) for the information and is offering network takedown of affected organisations for an unspecified amount.

The security firm believes that if the information falls into wrong hands, it has the potential of becoming a major tool of mass disruption.

The organisations whose services are most likely to be affected if the data gets leaked are: UIDAI (Aadhaar), Employees' Provident Fund Organisation, Idea Telecom, Bombay Stock Exchange (BSE), Flipkart, DRDO, Aircel, Reserve Bank of India, BSNL, SBI, TCS, ISRO, ICICI Prudential Mutual Fund, VMWare and several other Indian government portals, among others.

Talking to IANS, Rohit Srivastwa, Senior Director, Cyber Education and Services at Quick Heal said, "We have alerted the government authorities well within time. If someone gets control over this massive data that is currently up for sale on DarkNet, the above-mentioned organisations and enterprises can get affected.”

For the uninitiated, a DarkNet can be best described as any overlay network that can be accessed only with specific software, configurations, or authorization, often using non-standard communications protocols and ports. Two typical darknet types are friend-to-friend networks (usually used for file sharing with a peer-to-peer connection) and privacy networks such as Tor.

Related Reading: What is Dark Web and How It Works

According to Seqrite, after they spotted the advertisement, they ran a detailed investigation, which revealed the identity of the affected organisation to be India's national Internet registry IRINN (Indian Registry for Internet Names and Numbers) which comes under National Internet Exchange of India (NIXI).

Their next step was to bring Asia Pacific Network Information Centre (APNIC) and Indian government authorities up to catch with what had happened and recommend them to quickly alert all the potentially affected organisations to change their passwords and get their servers and systems patched with latest updates.

The security firm researchers also reveal that the hacker selling the data claims that he has the ability to tamper the IP allocation pool. If this indeed is true, it could end up causing a massive outage or Denial of Service (DoS) attack-like situation.

“This could impact various content delivery network (CDN) and hosting providers as well. If the hacker gets an interested buyer, then an attack on the system could disrupt Internet IP allocation and affect Internet services in India," read the company statement.

Along with the access, the seller is also ready to give credentials and various contractual business documents. He also claims to be in the possession of a large database of Asia Pacific Network Information Centre (APNIC).

Yesterday, we reported how an IBM study had deduced that despite of having such talented workforce, India is still unprepared to protect itself if a cyberattack to the scale of ‘WannaCrypt’ or ‘Petya’ ever hits home turf.

According to a recent IBM study conducted by Ponemon Institute, while the average cost of a data breach in 2017 decreased by 10 per cent globally when compared to the 2016 figure, but for the Indian enterprises, it grew by 12.3 percent from Rs 97.3 million in 2016 to Rs 110 million in 2017.

This development was first reported in Firstpost.

[Image: Appknox ]

Stolen Data From Over 6,000 Indian Businesses Available On Darknet, Claims Quickheal

In a worrying piece of news coming in for the Indian companies, a forum on DarkNet is reportedly selling data stolen from over 6,000 Indian businesses that includes Internet Service Providers (ISPs), some of the key government organisations, banks and enterprises. The advertisement was recently spotted by global IT security firm Quick Heal's Enterprise Security brand Seqrite.

In a company statement, Seqrite shared further details about the advertisement they discovered along with its partner seQtree InfoServices. According to the statement, the mastermind hacker behind the advertisement is demanding 15 Bitcoins (nearly INR 42 lakh) for the information and is offering network takedown of affected organisations for an unspecified amount.

The security firm believes that if the information falls into wrong hands, it has the potential of becoming a major tool of mass disruption.

The organisations whose services are most likely to be affected if the data gets leaked are: UIDAI (Aadhaar), Employees' Provident Fund Organisation, Idea Telecom, Bombay Stock Exchange (BSE), Flipkart, DRDO, Aircel, Reserve Bank of India, BSNL, SBI, TCS, ISRO, ICICI Prudential Mutual Fund, VMWare and several other Indian government portals, among others.

Talking to IANS, Rohit Srivastwa, Senior Director, Cyber Education and Services at Quick Heal said, "We have alerted the government authorities well within time. If someone gets control over this massive data that is currently up for sale on DarkNet, the above-mentioned organisations and enterprises can get affected.”

For the uninitiated, a DarkNet can be best described as any overlay network that can be accessed only with specific software, configurations, or authorization, often using non-standard communications protocols and ports. Two typical darknet types are friend-to-friend networks (usually used for file sharing with a peer-to-peer connection) and privacy networks such as Tor.

Related Reading: What is Dark Web and How It Works

According to Seqrite, after they spotted the advertisement, they ran a detailed investigation, which revealed the identity of the affected organisation to be India's national Internet registry IRINN (Indian Registry for Internet Names and Numbers) which comes under National Internet Exchange of India (NIXI).

Their next step was to bring Asia Pacific Network Information Centre (APNIC) and Indian government authorities up to catch with what had happened and recommend them to quickly alert all the potentially affected organisations to change their passwords and get their servers and systems patched with latest updates.

The security firm researchers also reveal that the hacker selling the data claims that he has the ability to tamper the IP allocation pool. If this indeed is true, it could end up causing a massive outage or Denial of Service (DoS) attack-like situation.

“This could impact various content delivery network (CDN) and hosting providers as well. If the hacker gets an interested buyer, then an attack on the system could disrupt Internet IP allocation and affect Internet services in India," read the company statement.

Along with the access, the seller is also ready to give credentials and various contractual business documents. He also claims to be in the possession of a large database of Asia Pacific Network Information Centre (APNIC).

Yesterday, we reported how an IBM study had deduced that despite of having such talented workforce, India is still unprepared to protect itself if a cyberattack to the scale of ‘WannaCrypt’ or ‘Petya’ ever hits home turf.

According to a recent IBM study conducted by Ponemon Institute, while the average cost of a data breach in 2017 decreased by 10 per cent globally when compared to the 2016 figure, but for the Indian enterprises, it grew by 12.3 percent from Rs 97.3 million in 2016 to Rs 110 million in 2017.

This development was first reported in Firstpost.

[Image: Appknox ]

Market Reports

Market Report & Surveys
IndianWeb2.com © all rights reserved