Personal Data of 7 Million Indian Credit, Debit Cardholders Leaked Through Dark Web

The leaked data appears to have some records that dates back to 2004.

Advertisement
By Jagmeet Singh | Updated: 10 December 2020 16:26 IST
Highlights
  • A researcher discovered a link carrying the data on dark Web
  • It included information such as PAN card numbers and employer details
  • The researcher was able to verify the leaked details

The leaked data exposes income levels and even first swiping amount of individuals

Sensitive data related to around seven million credit and debit cardholders has surfaced online through dark Web, according to a security researcher. The data included not only the names of affected Indian cardholders but also their mobile numbers, income levels, email addresses, and Permanent Account Number (PAN) details. It is available for download through a Google Drive link. The link is open for public access and is said to be in circulation on the dark Web for some days now.

Cybersecurity researcher Rajshekhar Rajaharia discovered the Google Drive link from the dark Web earlier this month. It was in circulation with the title “Credit Card Holders data” by some anonymous people, Rajaharia said.

Advertisement

The link, that was shared with Gadgets 360, included 59 Excel files that contained the data including the full names, mobile numbers, cities, income levels, and email addresses of cardholders. It also included PAN card numbers, employer details, and type of bank account linked with the employers of the affected credit and debit card users. However, the leaked data doesn't include the bank account and card numbers of the victims.

Rajaharia told Gadgets 360 that he was able to verify some names listed in the Excel files by finding them on LinkedIn or searching the surfaced mobile numbers on caller ID app Truecaller. He even found his name there while verifying the details.

Advertisement

Although the data doesn't contain any clear references to the banks whose cardholders' details have been leaked, it includes the first swipe amount for most of the cardholders. There are also details to show whether the affected cardholders enabled mobile alerts on their phones.

“The data may belong to some third party that provides service or leads to banks,” Rajaharia said, who initially reported the leak to Inc42.

Advertisement

The exact period from which the data has been leaked is unclear. However, it is likely to include details from mostly between 2010 and early 2019. In some cases, though, the data exposed cardholders' information dating back to 2004.

“The data is related to financial products, and since most of the people exposed are professionals, it's quite expensive,” noted Rajaharia.

Advertisement

Gadgets 360 has reached out to CERT-In for clarity on the leak and will update this space when the agency responds.

Experts believe that being a financial data leak, the information available through the dark Web could be used by attackers for phishing and malware attacks. Karmesh Gupta, CEO of cybersecurity firm WiJungle, told Gadgets 360 that the data surfaced might also used to initiate fraud calls.

"One of the fortunate thing is that leaked data is of employees of multinationals & large corporates and since major of them are cyber-aware so they are less likely to be the victim," said Gupta. "On the other hand, the bad part is since it is difficult to identify whom this data belongs to so it will be difficult to aware the compromised users about such a leak formally until someone comes forward and do it selflessly for the betterment of society."

This is not the first time when sensitive information of a large number of individuals in India has been exposed online. In October, the personal website data of Prime Minister Narendra Modi surfaced on the dark Web. The data leak reportedly included names, email addresses, and mobile numbers of lakhs of individuals. Last year, debit and credit card data of over 1.3 million Indian banking customers was also put on sale on the dark Web by cybercriminals.


Should the government explain why Chinese apps were banned? We discussed this on Orbital, our weekly technology podcast, which you can subscribe to via Apple Podcasts, Google Podcasts, or RSS, download the episode, or just hit the play button below.

Affiliate links may be automatically generated - see our ethics statement for details.
 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement
Popular Mobile Brands
  1. Netflix Games Launches FIFA World Cup: Launch Edition Ahead of FIFA World Cup 2026
  2. OnePlus Turbo 6X, OnePlus Turbo 6X Pro Key Specifications Teased
  3. Xiaomi Pad 8 Price Increased: Here's How Much It Costs Now
  4. Asics Refreshes GEL-Kayano Series With New Stability, Cushioning Upgrades
  5. Tecno Pova 8 to Launch in India With 8,000mAh Battery on This Day
  6. From iOS 27 to Revamped Siri, What to Expect from WWDC 2026
  1. Sahara Meteorite May Be Fragment of a Lost Moon-Sized World, Study Suggests
  2. OpenAI Introduces Smarter ChatGPT Memory, Adds Dreaming Architecture
  3. Tecno Pova 8 India Launch Date Announced; Battery Size, Design, Colour Options Teased
  4. Samsung Reportedly Starts Internal Testing of Android 17-Based One UI 9 for Galaxy S25 Series
  5. Bybit Lists Western Union’s USDPT Stablecoin for Trading and Transfers
  6. Xiaomi Pad 8 Price Hiked in India: Here’s How Much It Costs Now
  7. Instagram Reels Influencing Nearly Half of Purchase Decisions in India, Meta Study Claims
  8. OnePlus Turbo 6X, OnePlus Turbo 6X Pro Colour Options, Price Range, Key Specifications Teased
  9. Sattendru Maarudhu Vaanilai Now Streaming Online: Where to Watch Jai’s Romantic Thriller Movie
  10. Asics GEL-Kayano 33 Launched in India With New Stability Tech, FluidSupport System
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.