31 Oct 2023

The dark web is a hidden part of the internet that is not accessible by regular browsers or search engines. It is often used for illegal activities, such as hacking, drug trafficking, and cybercrime. Recently, a massive data breach has been reported on the dark web, involving the personal details of over 81.5 crore Indian citizens. This could be one of the biggest data breaches in Indian history, and it poses a serious threat to the privacy and security of millions of people.

What happened?

The Breach

On August 7, 2023, a massive data breach was reported in India. According to the US-based cybersecurity firm Resecurity, the personal information of over 81.5 crore Indian citizens was found on sale on the dark web. The compromised data includes sensitive information such as Aadhaar and passport numbers, as well as names, phone numbers, and addresses. The data sets on sale contain crucial information such as Aadhaar and passport details, along with names, phone numbers, and addresses. The details were a part of the Indian Council of Medical Research’s (ICMR) database.

The data breach noticed by Resecurity mentioned that "on October 9, a threat actor going by the alias ‘pwn0001’ posted a thread on Breach Forums brokering access to 815 million ‘Indian Citizen Aadhaar and Passport’ records". The cybersecurity analysts found one of the leaked samples containing 100,000 records of PII (personally identifiable information) related to Indian residents. In this sample leak, the analysts identified valid Aadhaar Card IDs, which were corroborated via a government portal that provides a “Verify Aadhaar” feature. The analysts also managed to connect with the threat actor and learned they were willing to sell the entire Aadhaar and Indian passport dataset for $80,000 (over Rs 66 lakh).

How serious is this breach?

This breach is extremely serious for several reasons:

  • The data contains sensitive personal information that can be used for identity theft, fraud, phishing, blackmailing, and other malicious purposes.
  • The data also contains COVID-19 test data, which can reveal the health status and medical history of millions of people. This can have serious implications for their insurance, employment, and social stigma.
  • The data breach affects a large number of people, almost two-thirds of India’s population. This makes it one of the largest data breaches in the world in terms of the number of records compromised.
  • The data breach exposes the vulnerability of India’s digital infrastructure and raises questions about the security and privacy practices of government agencies and private entities that handle such data.

The Implications

The implications of this breach are far-reaching. It is believed that the stolen data could be used for identity theft, financial fraud, and other criminal activities. The fact that this data is being sold on the dark web means that it is available to anyone who is willing to pay for it. This puts millions of Indians at risk of identity theft and other forms of cybercrime.
The Indian government has been quick to respond to this breach. The Central Bureau of Investigation (CBI) is expected to probe the incident after the ICMR files a complaint. However, it remains to be seen what action will be taken against those responsible for this breach.

What Can You Do?

If you are an Indian citizen and are concerned about your personal information being compromised in this breach, there are a few steps you can take:

  1. Check if your data has been compromised: You can check if your data has been compromised by visiting the official website of UIDAI (Unique Identification Authority of India).
  2. Change your passwords: If you have used any of the compromised information as your password for any online accounts, it is recommended that you change your passwords immediately.
  3. Be vigilant: Keep an eye out for any suspicious activity related to your bank accounts or other online accounts. If you notice anything unusual, report it immediately.

In conclusion, this breach highlights the need for stronger cybersecurity measures in India. It is imperative that both individuals and organizations take steps to protect their personal information from cybercriminals.


The data breach of 81.5 crore Indians on the dark web is a shocking and alarming incident that highlights the need for better data protection and cybersecurity measures in India. The government and other stakeholders must take swift and effective actions to investigate this incident, identify and punish the culprits, secure the data, and prevent such breaches from happening again. The citizens must also be aware of the risks and take precautions to safeguard their personal information online.

What do you think about this data breach? How do you protect your personal data online? Share your thoughts with us in the comments section below. Stay tuned for more updates on this topic in the next part of this article.

This is so bad for the people involved that's why you got to be careful every place you drop your personal data
It's really serious issue now a days personal data sharing is one type of business so that the we should very careful regarding sharing our personal data in some other place or web sites. Thank you for the article.
The security of personal data is paramount in today's digital age. The article sheds light on the alarming fact that a vast amount of personal information is available on the dark web. It serves as a stark reminder of the ongoing need for stringent data protection and cybersecurity measures.
Nice and interesting article. Thank you