Hathway, a prominent Indian Internet Service Provider (ISP) and cable television operator, has reportedly suffered a significant data breach, with a hacker known as 'dawnofdevil' leaking a database associated with the company. According to the hacker's post on Breach Forums, the breach occurred in December 2023, exploiting a security vulnerability in Hathway's Laravel framework application, which serves as the content management system (CMS). The hacker provided two links in the forum post, with the first link containing 12GB of user data, purportedly encompassing the personal details of over 41 million Hathway customers. This data includes full names, email addresses, phone numbers, home addresses, customer registration forms, copies of Aadhar cards, and other sensitive information such as KYC data. However, a subsequent analysis suggested that the actual number of impacted accounts is closer to 4 million after eliminating duplicates and dummy accounts. The second link, comprising a substantial 214GB of information distributed across over 800 CSV files, contains personal and financial details believed to belong to a combination of Hathway employees and customers. The hacker initially attempted to sell the data for $10,000 but, facing unsuccessful attempts to find a buyer, eventually opted to publicly leak the information. In an unusual move, 'dawnofdevil' developed a dark web search engine for potential victims of the data breach, allowing individuals to check if their email addresses and phone numbers are involved. Hathway has been contacted for comment, and the situation is currently evolving. Hathway customers are advised to remain vigilant for potential phishing emails related to the incident, as the leaked data does not include passwords.
Hackers are exploiting fake CAPTCHA pages to trick users into sending large volumes of international SMS messages, turning routine “prove you’re human” checks into a profitab...
A critical vulnerability has been identified in the Breeze Cache plugin for WordPress, actively exploited by attackers to upload arbitrary files without authentication. Tracked as ...
UNC6692 is a threat cluster conducting targeted social engineering campaigns by impersonating IT helpdesk staff through Microsoft Teams. Instead of exploiting software vulnerabilit...