RailYatri data on more than 31 million users posted to a hacking forum
- Organization
- RailYatri
- Exploit
- Hacking
- Industry
- Travel Technology
A database attributed to the Indian train travel booking platform RailYatri was posted on the cybercrime forum BreachForums on 16 February 2023, exposing records on more than 31 million users.
Inc42 reported the dump at 31,062,673 users and roughly 12.33 GB, containing email addresses, full names, genders, telephone numbers and locations. Have I Been Pwned, which later indexed the data, counted 23.2 million unique email addresses and listed the exposed fields as email addresses, names, genders, phone numbers and tickets purchased, including travel information and fares. Security researcher Anurag Sen flagged the posting.
RailYatri disputed that it had suffered a fresh intrusion. The company said the material was old data exposed in December 2022 and that it had since taken the necessary steps to protect user information. Have I Been Pwned dates the breach to December 2022, consistent with that account, and added the records to its index on 5 December 2023.
It was not the platform's first exposure. In 2020 a misconfigured Elasticsearch server left the records of about 700,000 people accessible, and the system was secured after India's CERT-In intervened in August that year.
Sen told Inc42 that companies in India were not being fined over data leaks because the country had no GDPR style law. No regulator announced action against RailYatri as of the reporting date.