BigBasket faces potential data breach; details of 20 mn users put on sale

Names, email IDs, password hashes, contact numbers, addresses of users put on sale on dark web, claims cyberintelligence firm Cyble

bigBasket, online data breach, e-commerce, privacy, data, hacking
BigBasket has lodged a complaint with the city’s Cyber Crime Cell and is currently evaluating the extent of the breach | Imaging: Ajay Mohanty
Samreen Ahmad Bengaluru
3 min read Last Updated : Nov 09 2020 | 1:22 AM IST
Online grocery platform BigBasket has become the latest target of cyberattack in India.

The company has faced a potential data breach with the information of over 20 million customers on the darkweb for sale, according to US-based cybersecurity intelligence firm Cyble.

The data, being sold for $40,000, includes the full names, email IDs, password hashes (potentially hashed OTPs), PIN, contact numbers, addresses, dates of birth, location, and IP addresses of login, among other bits of information, says a Cyble blogpost.

The Bengaluru-based start-up has lodged a complaint with the city’s cybercrime cell and is evaluating the extent of the breach and authenticity of the claim in consultation with cyber security experts.

“The privacy and confidentiality of our customers are our priority and we do not store any financial data, including credit card numbers, and are confident that this financial data is secure,” said the Alibaba-backed company in a statement.

“The only customer data we maintain are email IDs, phone numbers, order details, and addresses so these are the details that could potentially have been accessed. We have a robust information security framework that employs best-in-class resources and technologies to manage our information,” it added.

According to the Cyble blogpost, the alleged breach occurred on October 14 and the BigBasket management was informed about it on November 1.

While online commerce has made lives easier, this convenience could come at a cost, say experts.

Last month, Hyderabad-based pharmaceuticals company Dr Reddy’s had to shut its plants across the globe after a cyberattack on its servers. In May this year, Facebook-backed edtech start-up Unacademy had become the target of cyber attack with the data of over 20 million of the platform’s users leaked and put on sale on the darkweb.

According to an IBM survey, the average cost of a data breach in India touched ~14 crore in 2020, an increase of 9.4 per cent from last year, as the average time to contain a data breach increased from 77 to 83 days a year. The top three root causes of data breach are malicious attacks, system glitches, and human error in the country, added the report.

While the opinion is uniform that data is a critical asset that can help sharpen business outreach and increase profits, it should be treated as a tradeable asset, say experts.

“Instead of treating it as a commodity that needs to be hidden behind large security measures, the industry and regulatory bodies need to move towards treating data as a tradeable asset and data economy infrastructure wherein consumers will be more comfortable and slightly richer and data pirates have less of an incentive to breach and sell it,” said Ankit Chaudhari, chief executive officer and founder, Aiisma, a data marketplace.

“Or else security will keep becoming expensive and hackers sophisticated, a scenario in which neither consumer nor company wins,” Chaudhari added.

One subscription. Two world-class reads.

Already subscribed? Log in

Subscribe to read the full story →
*Subscribe to Business Standard digital and get complimentary access to The New York Times

Smart Quarterly

₹900

3 Months

₹300/Month

SAVE 25%

Smart Essential

₹2,700

1 Year

₹225/Month

SAVE 46%
*Complimentary New York Times access for the 2nd year will be given after 12 months

Super Saver

₹3,900

2 Years

₹162/Month

Subscribe

Renews automatically, cancel anytime

Here’s what’s included in our digital subscription plans

Exclusive premium stories online

  • Over 30 premium stories daily, handpicked by our editors

Complimentary Access to The New York Times

  • News, Games, Cooking, Audio, Wirecutter & The Athletic

Business Standard Epaper

  • Digital replica of our daily newspaper — with options to read, save, and share

Curated Newsletters

  • Insights on markets, finance, politics, tech, and more delivered to your inbox

Market Analysis & Investment Insights

  • In-depth market analysis & insights with access to The Smart Investor

Archives

  • Repository of articles and publications dating back to 1997

Ad-free Reading

  • Uninterrupted reading experience with no advertisements

Seamless Access Across All Devices

  • Access Business Standard across devices — mobile, tablet, or PC, via web or app

Topics :BigBasketCyberattacksData breach

Next Story