Saturday, January 25, 2025
HomeCyber Security NewsPersonal Data of 458,388 Delhi Citizens Exposed Online from an Unprotected Database

Personal Data of 458,388 Delhi Citizens Exposed Online from an Unprotected Database

Published on

SIEM as a Service

Follow Us on Google News

A database that contains highly sensitive information of about 458,388 individuals located in Delhi exposed for public access without any password protection.

Security researcher Bob Diachenko discovered the publically exposed database name “GNCTD” that indexed by Shodan.

The 4.1GB-sized MongoDB belongs to Government of National Capital Territory of Delhi and by analyzing contents Bob Diachenko concluded the database belongs to company named Transerve and it incluudes the following.

Delhi
  • EB* Registers
  • EB Users (14,861)
  • Households (102,863)
  • Individuals (458,388)
  • Registered Users (399)
  • Users (2,983)

The database contains the registered users of transerve with the Email addressed @transerve.com including the email address that has the admin level permissions with the hashed passwords.

Delhi

Database contains two collections that has a detailed information about the individuals.

Individuals Collection details about a person that includes Aadhaar numbers, voter card numbers, health conditions, education, etc.

Households collection includes fields such as name’, ‘house no’, ‘floor number’, ‘geolocation’, area details, ’email_ID’ of a supervisor, ‘is the household cooperating for survey’ field, ‘type of latrine’, ‘functional water meter’, ‘ration card number’, ‘internet facility available’ and even ‘informan name’ field.

Delhi

Bob Diachenko contacted Transerve and there is no response, then he contacted CERT India and then the databse has been secured and taken offline.

We cannot say for sure that this database is connected to GNCTD, but that is highly likely based on the evidence, it remains unknown for how long the database is online without the password.

The exposed data could be a stepping stone for attackers to launch a high profile attack targeting the indivicuals.

MongoDB published a security checklist that provides a list of security measures that server administrators should implement to protect your MongoDB installation.

Also Read

Reddit Data Breach – Hackers Stolen Users’ Email Address and Credentials

10 Million Customers Personal Records Leaked in Dixons Carphone Massive Data Breach

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Subaru’s STARLINK Connected Car’s Vulnerability Let Attackers Gain Restricted Access

In a groundbreaking discovery on November 20, 2024, cybersecurity researchers Shubham Shah and a...

Android Kiosk Tablets Vulnerability Let Attackers Control AC & Lights

A security flaw found in Android-based kiosk tablets at luxury hotels has exposed a...

CISA Releases Six ICS Advisories Details Security Issues

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued six Industrial Control Systems (ICS)...

Juniper Routers Exploited via Magic Packet Vulnerability to Deploy Custom Backdoor

A sophisticated cyber campaign dubbed "J-magic" has been discovered targeting enterprise-grade Juniper routers with...

API Security Webinar

Free Webinar - DevSecOps Hacks

By embedding security into your CI/CD workflows, you can shift left, streamline your DevSecOps processes, and release secure applications faster—all while saving time and resources.

In this webinar, join Phani Deepak Akella ( VP of Marketing ) and Karthik Krishnamoorthy (CTO), Indusface as they explores best practices for integrating application security into your CI/CD workflows using tools like Jenkins and Jira.

Discussion points

Automate security scans as part of the CI/CD pipeline.
Get real-time, actionable insights into vulnerabilities.
Prioritize and track fixes directly in Jira, enhancing collaboration.
Reduce risks and costs by addressing vulnerabilities pre-production.

More like this

Android Kiosk Tablets Vulnerability Let Attackers Control AC & Lights

A security flaw found in Android-based kiosk tablets at luxury hotels has exposed a...

CISA Releases Six ICS Advisories Details Security Issues

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued six Industrial Control Systems (ICS)...

PayPal Fined $2 Million Fine For Violating Cybersecurity Regulations

The New York State Department of Financial Services (NYDFS) has imposed a $2 million...