On October 9th, a threat actor going by the alias ‘pwn0001’ posted a thread on Breach Forums brokering access to 815 million “Indian Citizen Aadhaar & Passport” records. To put this victim group in perspective, India’s entire population is just over 1.486 billion people.
HUNTER investigators established contact with the threat actor and learned they were willing to sell the entire Aadhaar and Indian passport dataset for $80,000.
The data set offered by pwn0001 contains multiple fields related to the PII of Indian citizens, including but not limited to:
– name
– father’s Name
– phone Number
– other Number
– passport Number
– aadhar Number
– age
– gender
– address
– district
– pincode
– state…
One of the leaked samples contains 100,000 records of personal identifiable information (PII) related to Indian residents. In this sample leak, HUNTER analysts identified valid Aadhaar Card IDs, which were corroborated via a government portal that provides a “Verify Aadhaar” feature. This feature allows people to validate the authenticity of Aadhaar credentials,” Resecurity said…
Resecurity acquired… 400,000 records and contacted multiple victims to validate the information, as well as used the “Verify Aadhaar” feature available via official government WEB-resource in India.
The contacted victims from the acquired data set confirmed the validity of their data, and stated they have never been notified about [the breach] before.