D_C
March 29, 2021, 8:45pm
1
The data that’s on offer includes a total of 350 gigabytes of MySQL dumps that include 500 databases. It also consists of 99 million mail, phone passwords, addresses and data surrounding installed apps, IP addresses, GPS locations etc.
https://www.bgr.in/news/mobikwik-data-leak-personal-data-of-3-5-million-users-up-for-sale-on-dark-web-company-denies-claims-950805/
Onion link-
http://mobikwikoonux37wauz6oqymshuvebj5u763rutlogc2fb2o3ugcazid.onion/
I checked my details, matches what I had in my mobikwik profile. Checked for my friend, he confirmed the card details are correct.
Edit: password is hashed and card details partially blanked. I am assuming the leaker has them in full clear text, just removed them for public viewing.
3 Likes
JMP
March 29, 2021, 8:50pm
2
Were you able to access the onion link?
The link never worked for me.
D_C
March 29, 2021, 8:53pm
3
Yes, but it works intermittently. Failed to connect to backed errors. I tried after a few minutes. Try a new node or refresh your tor connection.
Apparently, the breach happened on 4th March. Lots of people confirming data leak is real.
Edit- Onion link seems to be down now.
mk76
March 30, 2021, 6:32am
4
Earlier they had denied. But several users are responding to this tweet.
Onion link for those who want to try
1 Like
Tor link for the compromised stuff:
http://mobikwikoonux37wauz6oqymshuvebj5u763rutlogc2fb2o3ugcazid.onion/?fbclid=IwAR1bn1dSVAx4ZRsZSbjIae4-JzFlKyHY-f7Bi84Jcle2kVP1j__Blt8g_aI
Use Tor.
Thankfully I never did my KYC with them. But my email, phone, bank account details are visible.
1 Like
How did you search? The search bar didn’t work for me
Onion link is working fine and its a very serious issue. govt is encouraging digitization but not at all serious for making law for data protection.
1 Like
D_C
March 30, 2021, 7:08am
8
Yup, unless there is a law to mandate good data security practices and severe fines for breaches, the companies have no incentive to actually care and spend money on data security.
iPwnz
March 30, 2021, 7:08am
9
Looks like they are preparing a press release because they haven’t said anything.
D_C
March 30, 2021, 7:10am
10
Their latest tweet since the breach.
Again, Not surprised at all. The key weakness with most mobile app/service startups is not investing enough in information security. They spend a lot on marketing and this is the price they pay.
JMP
March 30, 2021, 8:55am
13
I was able to access the site via tor this time, but the search feature is now disabled.
iPwnz
March 30, 2021, 9:03am
14
Hackersnews also picked it up. They won’t be able to ignore anymore lol.
1 Like
Bunch of bafoons, they should be penalized for this. Pancard, aadhar cards, photos, address, credit card numbers (masked) everything is available.
This is a criminal offence.
1 Like
D_C
March 30, 2021, 10:17am
16
Blog update- https://blog.mobikwik.com/message-from-the-company/
Oh yes, who would have thought that people usually upload same identity documents for KYC. Because they are ID proofs! That’s how ID proof works.
5 Likes
iPwnz
March 30, 2021, 10:35am
17
Omg they are still in denial lol.
Speechless.
Seriously man, what pieces of shit. This needs to be penalised.
Other payment services and other services in general that collect such sensitive user information should learn from this and strengthen their security.
1 Like
Glad not to have done any KYC with them. Although had added a few credit card details into it.
Always got that shady vibe when using the app.