Unsecured Database Found Leaking Data About Millions of Indians, Gets Hijacked by Hackers: Report

The database was accessible to anyone for over two weeks.

Advertisement
By Gaurav Shukla | Updated: 10 May 2019 14:02 IST
Highlights
  • The unprotected database was publicly indexable
  • It was crawled by Shodan search engine on April 23, 2019
  • The hacker group Unistellar has now got hold of the database

The database included information like name, email, mobile number, salary, date of birth, and more

A massive database containing over 275 million records with personally identifiable information about Indian citizens was allegedly found unprotected and publicly indexed on the Internet. Discovered by a cybersecurity expert, this MongoDB database seems to include data scrapped from various job portals, given the fields in the database like “industry,” “resume ID,” and “functional area.” While some of professional information present in the database isn't that damaging, the database also included details like name, email address, gender, date of birth, salary, and mobile number, access to which can be exploited by malicious parties. MongoDB is a widely used open-source database management system.

Found by security researcher Bob Diachenko from Securitydiscovery.com on May 1, the database has since been hijacked by hackers known as “Unistellar group”, who have replaced it with a message to contact to restore it, possibly in an exchange of a ransom. If the database being left unprotected wasn't bad enough, it is now in hands of a hacker group, who may be willing to sell it to anyone.

The unprotected database had a size of 110GB
Photo Credit: Securitydiscovery.com

Advertisement

According to Diachenko, he had immediately contacted Indian Computer Emergency Response Team (CERT) about the unprotected database, but the database remained accessible until May 8, following which it was hijacked by the Unistellar group.

Advertisement

The data available with Shodan, a search engine for Internet-connected devices, reveals that the database was first indexed on April 23, 2019, meaning it was available on the Web for at least two weeks for anyone to access the private information.

It is unclear at this point, who was the owner of the database, but Diachenko speculates that it belonged to an “anonymous person or organization” as part of a massive scraping operation. The owners of the database have seemingly managed to scrap over 275,265,298 records of personal information about Indian job seekers. Diachenko's assertions about database owner seem plausible considering none of Indian job portals, have anywhere close to 275 million members.

Advertisement

The database has now been hijacked by a hacker group
Photo Credit: Securitydiscovery.com

Advertisement

This is not the first time that Diachenko has found an unprotected database leaking private information of millions of users online. Last month, he discovered an Indian state (unnamed) had left details of millions of pregnant women online. The data leak included digitised version of millions of medical forms that included private details.

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Further reading: Data Leak, Hack
Advertisement

Related Stories

Popular Mobile Brands
  1. iQOO Neo 11: Launch Date, Expected Price, Design, Specifications, Features, and More
  2. Revolutionary Semi-Transparent Solar Cells Could Turn Windows into Power Generators
  1. Semi-Transparent Solar Cells Break Records, Promise Energy-Generating Windows and Facades
  2. Chang’e-6 Lunar Samples Reveal Water-Rich Asteroid Fragments
  3. James Webb Telescope Uncovers the Turbulent Birth of the First Galaxies
  4. Troll 2 OTT Release Date: When and Where to Watch it Online?
  5. Baramulla OTT Release Date: When and Where to Watch Gripping Thriller Set in the Heart of Kashmir Online?
  6. Lazarus Now Streaming on Amazon Prime Video: What You Need to Know
  7. Gemini October Feature Drop Brings New Features to Veo 3.1, Gemini 2.5 Flash, Canvas, and More
  8. Nothing Phone 3a Lite Reported to Launch in Early November: Expected Price, Specifications
  9. HMD Fusion 2 Key Features, Specifications Leaked Online: Snapdragon 6s Gen 4, New Smart Outfits, and More
  10. Google Says Its Willow Chip Hit Major Quantum Computing Milestone, Solves Algorithm 13,000X Faster
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.