While the threat actor does not mention the name of an organization, the data provided in the sample is clearly associated with a police exam conducted on 22 Dec 2019.
Discovery of the leak
CloudSEK’s proprietary risk monitoring tool XVigil discovered a post on a popular surface web forum on 29 January 2021. The actor claims to have 500,000 records and has shared a sample of the leak that contains the data of 10,000 users. For more records, the threat actor has to be reached via email or Telegram.
Contents of the leak
The sample CSV file, shared over a file hosting link, contains 10,452 records. Each record includes the following fields:
Data verification and validation
On analysing the sample, CloudSEK researchers identified that the common denominators of a significant amount of the sample data are Bihar (“wedistrict”) and 22 December 2019 (“wedate”). This points to the candidates of the preliminary examination conducted by Bihar Police Subordinate Services Commission (BPSSC) for the post of Sub Inspector/ Sergeant/ Assistant Superintendent Jail / Assistant Superintendent Jail, on 22 December 2019.
The mobile numbers provided in the sample have been validated against the candidate’s name.
The entire leaked database consists of ~500K records. Since the database includes sensitive data, i.e. name, mobile number, and PII, it makes the victims vulnerable to phishing campaigns, scams, and even identity theft.
About the Author: CloudSEK Threat Intelligence
If you want to receive the weekly Security Affairs Newsletter for free subscribe here.
(SecurityAffairs – hacking, Indian Citizens)
Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.