LIVE NEWSROOM · --:-- · May 25, 2026
A LIBRARY FOR SECURITY RESEARCHERS

IRCTC Data breach? Hacker claims to sell 3 Crore user’s data

Post on X LinkedIn
IRCTC Data breach? Hacker claims to sell 3 Crore user’s data

Hello everyone, lucifer here, and today we are going to discuss the Indian railway (IRCTC) data breach of 30 million users available on the dark web.

Recently on Tuesday, 27 December Indian railways came up with a data breach of approximately 3 crore users which was available for sale on the dark web.

This breach was claimed by a hacker named shadow hacker who was selling the 30 million user data of the Indian railway on a Hackers’ forum, this portal is generally used by cyber criminals to sell hacked data on the dark web.

Also, the hacker is not revealing the source of the data leaked.

Indian railway data breach
Images Credit Techlomedia

Irctc is not denying with the breach came up, but they are denying that the data is hacked from their official IRCTC servers.

Recently ANI said in a tweet that a railway spokesperson said that “On analysis of sample data, it is found that the sample data key pattern does not match with IRCTC history API. A suspected data breach is not from the IRCTC servers.”

Further Investigation is being done by IRCTC regarding the data breach. And All IRCTC business partners have been asked to immediately examine whether there is any data leakage from their end and apprise the results along with corrective measures taken to IRCTC.”

As hacker claims that he has two sets of data available for sale. The first set contains the user data which includes username, phone number, email, gender, city, state, and language preference in it.

And, the Second set contains the data of booking which includes the traveler’s name, mobile number, travel details, train number, invoice, and other information about ticket booking.

As a report given on Techlomedia, when some sample data provided by the hacker, were examined on the IRCTC website then it was found to a legit PNR data.

According to reports on the IRCTC website was used for booking approximately 430 million tickets in the 2021-22 financial year. And approximately 6.3 million daily logins and more than 80 million users of its online services.

According to the data available on the forum, the hacker provides five copies of data which costs around $400 per copy. The hacker also claims that to provide that data and vulnerability details for $2,000.

News Credit:- CNBC TV 18, The Economic Times, Techlomedia.

    TE
    Team Ciphers Security

    The Ciphers Security editorial team — practitioners covering daily threat intel, CVE deep-dives, and hands-on cybersecurity research. About us →

    Previous What is veil framework Next What is VPN and Proxy

    Latest News

    CISA Contractor Leaked AWS GovCloud Keys on GitHub for Six Months A Nightwing contractor exposed CISA's AWS GovCloud credentials and internal system keys on a public GitHub repo for… Ghostwriter Deploys Prometheus Phishing Lures Against Ukraine Government Entities Belarus-aligned APT Ghostwriter (UAC-0057) is targeting Ukrainian government with Prometheus-themed phishing delive… Screening Serpens: Iranian APT Fuses AppDomainManager Hijacking with New RATs in 2026 Espionage Campaign Iran-aligned Screening Serpens is using AppDomainManager hijacking and new RAT variants — MiniJunk and MiniUpdate —… CVE-2026-9082: Critical Drupal SQL Injection Under Attack on Thousands of Sites CVE-2026-9082 is an unauthenticated SQL injection in Drupal Core affecting PostgreSQL deployments across versions 8… CVE-2026-20182: Cisco Catalyst SD-WAN CVSS 10.0 Auth Bypass Actively Exploited CVE-2026-20182 (CVSS 10.0 Critical) is a Cisco Catalyst SD-WAN Controller auth bypass exploited by UAT-8616. Metasp… Kali365 PhaaS Kit Bypasses Microsoft 365 MFA via Device Code Phishing — FBI Warning FBI warns Kali365 PhaaS kit steals Microsoft 365 OAuth tokens, bypassing MFA. Hundreds of orgs compromised daily. A… Megalodon: Supply Chain Attack Backdoors 5,561 GitHub Repos in Six Hours via CI/CD Workflow Injection Megalodon supply chain attack compromised 5,561 GitHub repos in 6 hours on May 18, injecting malicious CI/CD workfl… Stolen Gemini API Keys and AI Fraud: How 'Quantum Patriot' Drained Crypto Wallets via Fake QAnon Content A Russian-speaking fraudster used 73 stolen Gemini API keys and an automated Python pipeline to generate fake QAnon…
    Scroll to Top
    Ad