Railyatri Security Flaw Could Have Exposed Debit Cards, UPI Data of 7 Lakh Passengers: Report

RailYatri exposed nearly 43GB of user data due to the security flaw.

Advertisement
By Shayak Majumder | Updated: 25 August 2020 09:56 IST
Highlights
  • RailYatri security flaw exposed user names, payment information
  • It was first spotted by Safety Detectives, a cyber-security firm
  • RailYatri has closed the unprotected server in question

RailYatri security flaw stemmed from an unprotected Elasticsearch server

RailYatri was reportedly left exposed due to inadequate security measures, that put the payment information and other personal data of lakhs of users at risk. As per the report, the data was saved on an unsecured server, and the ticket-booking platform potentially exposed personal information of over 7 lakh passengers. This includes full names, phone numbers, addresses, email IDs, ticket booking details, and partial credit or debit card numbers. The vulnerability that was first spotted by a team of cyber-security researchers on August 10.

As reported by The Next Web, the exposed Elasticsearch server was spotted by a team of researchers at cyber-security firm Safety Detectives on August 10. The security firm discovered that the affected server was left exposed without any encryption or password protection for several days. Safety Detectives said in its blog that anyone with the server's IP address could have gained access to the full database.

Advertisement

The blog pointed out that the data, amounting to nearly 43GB, mostly featured users based in India. The firm estimated that over seven lakh individuals were likely affected by the vulnerability.

Gadgets 360 has reached out to RailYatri for a statement. This report will be updated when we hear back.

Advertisement

Update: A company spokesperson denied the claims and said that it does not store "financial and other sensitive data," apart from some partial details. The spokesperson also stated that RailYatri only stores a day's worth of data, which would not amount to this scale of information.

At the time of writing, RailYatri didn't respond to The Next Web or Security Detectives, but closed the server after the security firm raised the matter with the government wing, Indian Computer Emergency Response Team (CERT-In).

Advertisement

On August 12, a Meow bot attack lead to the deletion of nearly the entire server data, according to Safety Detectives' blog post. The Meow bot is a new type of cyber-attack that deletes unsecured databases that run Elasticsearch, Redis, or MongoDB servers.

The database in question comprised over 37 million records, including log files. The type of information exposed contained full names, age, gender, physical/ email addresses, contact numbers, payment logs, UPI IDs, train and bus booking details, and travel itinerary information. It also carried partial records of credit and debit card information as well as the users' GPS location information.

Advertisement

Full statement from the RailYatri spokesperson, updated on August 25:

"At RailYatri, we take the safety and privacy of our user-base seriously, and as soon as the issue was brought to our notice by CERT-In (Indian Computer Emergency Response team) a week back, our team was instantly on its feet in efforts to resolve the issue then and there. Post receiving the information, the testing server port was plugged immediately from the network. The server in question was a test server, and some of our logs were partially replicated on the same. As a general protocol, any and all data older than 24 hours are automatically deleted from the server. Further, we would like to clarify that report suggesting 7,00,000 email addresses leaked in three days is factually incorrect as it would be impossible for that to happen since the server contains at most a days-worth of data.

Having said so, we would like to assure our users that RailYatri does not store financial and other sensitive data with the exception of some partial details. We do not store credit card data on our servers. Data privacy is of utmost importance to us, and we have taken a thorough look at the issue to address it comprehensively. We are committed to the safety of user data.”


Should the government explain why Chinese apps were banned? We discussed this on Orbital, our weekly technology podcast, which you can subscribe to via Apple Podcasts, Google Podcasts, or RSS, download the episode, or just hit the play button below.

Affiliate links may be automatically generated - see our ethics statement for details.
 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement
Popular Mobile Brands
  1. Marvel's Wolverine Gets Gameplay Trailer at State of Play, Pre-Orders Go Live
  2. Lumio Launches 55-Inch Variants of Vision 9 (2026), Vision 7 (2026) in India
  3. Here's Everything That Was Announced at Sony's State of Play Broadcast
  4. Motorola Edge 2026 With 6.3-Inch Display Goes Official
  5. RTX Spark-Powered Laptops Could Cost a Lot More Than Regular AI PCs
  6. Lava Bold N2 5G Launched in India With 6,000mAh Battery, 6.75-Inch Display
  7. Anthropic Brings Its Cybersecurity AI Model Claude Mythos to India
  8. Vivo X500 Pro Max Display and Battery Details Revealed in New Leak
  1. UK's FCA Warns Premier League Clubs Over Unauthorised Crypto Sponsor Risks
  2. Vivo X500 Pro Max Display and Battery Details Surface Online in Early Leak; Largest Model Said to Feature 6.85-Inch Screen
  3. Google Introduces Fake Call Detection for Android Phones to Curb Call Spoofing Attacks
  4. Google Rolls Out Gemini Thinking Levels Across Platforms With 'Extended' Thinking Mode for All Users
  5. Samsung Galaxy A27 Reportedly Bags US FCC Certification Ahead of Anticipated Launch
  6. NYDFS, European Banking Authority Join Forces to Oversee, Monitor Stablecoin Activities
  7. Meta Reportedly Testing ‘Series’ Feature to Organise Instagram, Facebook Reels Into Episodic Collections
  8. Xiaomi 18 Tipped to Sport 6.4-Inch Display; Pro Models Said to Feature Dual 200-Megapixel Rear Cameras
  9. Realme P4R 5G India Launch Date Revealed Along With Design and Key Specifications
  10. Marvel's Wolverine Gets Visceral Gameplay Trailer at State of Play, Pre-Orders Now Live
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.