Recently discovered by security researcher Alon Gal (Twitter/@UnderTheBreach), the BigBasket data breach wasconfirmed by the company back in Novemberof last year. Now, the data acquired in the hack has been publicly shared on the dark web. It can be accessed by anyone for free.
Gal shared the news via a tweet recently. So, as per the researcher, the leaked BigBasket data include names, email IDs, hashed passwords, phone numbers, and birthdates of 20 million users on the platform.
The attack has been carried out by an infamous threat actor dubbed “ShinyHunters”, and most importantly, the hacking group was able to acquire the hashed passwords of millions of users. These were, as per another security researcher Rajshekhar Rajaharia, allegedly decrypted by another hacker.
“This could lead to a serious problem for the affected customers as bad actors would gain access to their personal web accounts using the decrypted passwords and leaked email addresses,”RajahariatoldGadegets360.
So, if you are one of the millions of users on BigBasket, we would recommend you immediately change your BigBasket password. Moreover, you can go to the“Have I Been Pwned?”website, which is reportedly sending out emails to notify users about the BigBasket data leak, tocheck if your details are included in the leaked dataor not.
Bringing the latest in technology, gaming, and entertainment is our superhero team of staff writers. They have a keen eye for latest stories, happenings, and even memes for tech enthusiasts.