BigBasket Data Allegedly Leaked on Dark Web, Database Claimed to Include Details of Over 20 Million Users

BigBasket confirmed a data breach in November last year that is said to be associated with the latest leak.

Advertisement
By Jagmeet Singh | Updated: 26 April 2021 18:59 IST
Highlights
  • BigBasket’s alleged database included personal details of affected users
  • The database has been leaked by a hacker known as ShinyHunters
  • BigBasket has not yet confirmed the leak or informed its customers

BigBasket is one of most popular grocery delivery companies in India

BigBasket database of over 20 million customers has allegedly been leaked on the dark Web, months after the online grocery delivery platform confirmed a data breach. The alleged database includes the email addresses, phone numbers, and hashed passwords of the affected customers. The data also allegedly carries physical addresses and date of birth of BigBasket users. Although the database that is available for free access on the dark Web includes user passwords in an encrypted form, another hacker has claimed to have decrypted some of the leaked passwords.

The alleged BigBasket database has been put on the dark Web by a hacker group infamously known as ShinyHunters. It includes details such as the email addresses, names, date of birth, and phone numbers.

Advertisement

 

Cyber-security researcher Rajshekhar Rajaharia told Gadgets 360 that the leaked database is associated with the breach that BigBasket itself confirmed in November last year.

Advertisement

Update April 26, 6.56pm: BigBasket has responded to Gadgets 360 to confirm that this is indeed the November leak, and the company also highlighted that it has made changes to its systems to eliminate all hashed passwords, moving to an OTP-based mechanism instead, as a security measure. BigBasket's full statement is included at the end of this article.

“A few days ago, we learnt about a potential data breach at BigBasket and are evaluating the extent of the breach and authenticity of the claim in consultation with cybersecurity experts and finding immediate ways to contain it,” the company had said while confirming the data breach that was made public by cybersecurity intelligence firm Cyble.

Advertisement

ShinyHunters made the alleged BigBasket database available for download on the dark Web over the weekend. It included hashed passwords of the affected customers. However, some passwords in plain text are now also put on sale on the dark Web.

“Another hacker is claiming to have decrypted millions of passwords associated with BigBasket,” said Rajaharia. “This could lead to a serious problem for the affected customers as bad actors would gain access to their personal Web accounts using the decrypted passwords and leaked email addresses.”

Advertisement

Meanwhile, the website Have I Been Pwned? — that informs users on whether their data has been compromised by any recent breaches — has sent an email to notify some affected customers about the data leak.

Founded in 2011, BigBasket is backed by China's Alibaba and is one of the leading platforms for delivering groceries online. The pandemic helped the company expand its business and even attract conglomerate Tata Group that in February agreed to acquire a majority stake in the company.

Update: Full statement from BigBasket:

This article / social media post refers to an alleged data breach in Nov-2020 and not something that has happened recently. The reason we know it's not recent is that the article /social media post mentions the release of hashed passwords. We had eliminated all hashed passwords from our system and moved to a secure OTP-based authentication mechanism quite some time back. Also, our site does not collect or store any sensitive personal data of customers like credit card details. So customer data continues to be safe and no further action needs to be taken by customers.


Why did LG give up on its smartphone business? We discussed this on Orbital, the Gadgets 360 podcast. Later (starting at 22:00), we talk about the new co-op RPG shooter Outriders. Orbital is available on Apple Podcasts, Google Podcasts, Spotify, and wherever you get your podcasts.

Affiliate links may be automatically generated - see our ethics statement for details.
 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement
Popular Mobile Brands
  1. Oppo K15 Pro Series With Active Cooling Fan Launched: See Price
  2. iQOO 15 Apex Edition Arrives in India as a Special Variant of iQOO 15
  3. Google Finally Lets Users Change Their Gmail Address
  4. Lava Bold N2 Lite Arrives With a 5,000mAh Battery at This Price in India
  5. Gadgets360 Awards 2026: Check Out Winners of India's Most Trusted Awards
  6. Meta Launches First Prescription-Focussed Smart Glasses
  7. You Can Now Blinkit Chargers and Snacks Inside Mumbai Airport
  1. Samsung Galaxy A27 5G Visits Geekbench With Older Snapdragon 6 Gen 3 Chip, 6GB RAM
  2. Interactive Brokers Expands Crypto Trading to Retail Investors in Europe
  3. Blinkit Launches Inside Mumbai Airport, Lets Users Order Essentials From Across the Terminal
  4. Smartphone Exports From India Could See a Notable Decline as Iran Conflict Persists: Report
  5. Redmi A7 Pro Launched With 6,000mAh Battery, 13-Megapixel Rear Camera: Price, Features
  6. Gen Z Reportedly Dominates India’s Crypto Futures Market With 61 Percent Share
  7. Nvidia’s New DLSS 4.5 Update Brings AI-Powered 6X Multi-Frame Generation Feature
  8. Xbox Games Showcase Announced for June 7, Gears of War: E-Day to Get Deep Dive
  9. Apple's iOS 27 Update Expected to Include New ‘Alternative Words’ Keyboard Feature: Report
  10. OpenAI Raises $122 Billion in Latest Funding Round, Says Building Unified AI Superapp
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.