New Delhi: A significant data breach impacting the Bengaluru Water Supply and Sewerage Board (BWSSB) has exposed the sensitive personal information of over 290,000 customers. This incident, uncovered by the cybersecurity firm CloudSEK on 10th April, highlights critical vulnerabilities in data security within public utilities. The breached data, offered for sale on the BreachForum dark web marketplace by a hacker using the alias “pirates_gold”, includes Aadhaar numbers, PAN card details, addresses, phone numbers, email addresses, and even payment records.
Access to the compromised data was reportedly available for $500, approximately 42,000 Indian rupees. The attacker’s willingness to negotiate the price further underscores the gravity of the situation.
CloudSEKs report, published exclusively in the Deccan Herald, details the discovery by their XVigil platform, a threat monitoring system that scans the surface, deep, and dark web. The investigation revealed that the breach likely occurred due to exposed database credentials found in a publicly accessible configuration file, indicating a serious lapse in security protocols.
While BWSSB sources insist that billing data is stored securely at the Karnataka State Data Centre, the extent of the data breach raises considerable concern. The exposed data poses a significant risk to affected customers, making them vulnerable to phishing attacks and various forms of digital fraud.
The incident serves as a stark reminder of the importance of robust cybersecurity measures within public organisations. The accessibility of sensitive personal information to malicious actors raises questions about the adequacy of existing security protocols and the need for stricter data protection measures.
The potential consequences of such breaches extend beyond individual privacy violations; they impact public trust and potentially undermine the integrity of essential public services. Further investigation is warranted to fully assess the implications of this breach and to implement measures to prevent similar incidents in the future.