Hindustan Times (East UP)

‘Probable data breach at e-tailer BigBasket ’

- Press Trust of India feedback@livemint.com

Grocery e-commerce platform BigBasket has faced a potential data breach which could have leaked details of its around 2 crore users, according to cyber intelligen­ce firm Cyble.

The company has filed a police complaint in this regard with Cyber Crime Cell in Bengaluru and is verifying claims made by cyber experts.

Cyble said that a hacker has put data allegedly belonging to BigBasket on sale for around ₹30 lakh.

“In the course of our routine dark web monitoring, the research team at Cyble found the database of BigBasket for sale in a cyber crime market, being sold for over $40,000. The leak contains a database portion; with the table name ‘member_member’. The size of the SQL file is about 15 GB, containing close to 20 million user data,” Cyble said in its blog.

It added the data put on sale includes names, email IDs, password hashes, contact numbers (mobile and phone), addresses, date of birth, location, and IP addresses of login among many others.

While Cyble has mentioned “passwords”, the company uses a one-time password sent through SMS which keeps on changing every time a user logs in.

“A few days ago, we learnt about a potential data breach at BigBasket and are evaluating the extent of the breach and authentici­ty of the claim in consultati­on with cybersecur­ity experts and finding immediate ways to contain it. We have also lodged a complaint with the Cyber Crime Cell in Bengaluru and intend to pursue this vigorously to bring the culprits to book,” BigBasket said in a statement.

The company said that the privacy and confidenti­ality of customers is priority and it does not store any financial data including credit card numbers etc and is confident that this financial data is secure.

“The only customer data that we maintain are email IDs, phone numbers, order details, and addresses so these are the details that could potentiall­y have been accessed. We have a robust informatio­n security framework that employs bestin-class resources and technologi­es to manage our informatio­n. We will continue to proactivel­y engage with best-in-class informatio­n security experts to strengthen this further,” BigBasket said.

Cyble claimed that the breach occurred on October 30, 2020 and it has already informed the management of BigBasket about it.

 ?? BLOOMBERG ?? The e-com firm’s user data is being sold on the dark web, according to Cyble.
BLOOMBERG The e-com firm’s user data is being sold on the dark web, according to Cyble.

Newspapers in English

Newspapers from India