Tuesday, November 24, 2020
Personal data of Bharatmatrimony users breached says security firm Cyble Inc

Mumbai: Private information of shoppers of on-line matchmaking web site Bharatmatrimony.com suffered a breach and was obtainable on the market on the darkweb on Thursday, in response to Atlanta-based cyber safety agency Cyble. The corporate mentioned that it’s investigating the problem and added that there was “no breach of its present lively database of shoppers”.

In accordance with Cyble, the leaked information consists of delicate private data like names, telephone numbers, consumer IDs and date and time of account creation. A pattern of the leaked information has been reviewed by ET.

Buyer information price 1.7 GB belonging to hundreds of customers was up on the market in alternate for $500 in cryptocurrency, in response to researchers on the agency. ET couldn’t independently confirm the variety of customers whose information was compromised.

In its response to ET, a spokesperson for Matrimony.com mentioned, “We’re conscious of a safety difficulty that has been reported to us just lately. As per our investigation, there was no breach of our present lively database of shoppers. What has been reported belongs to an outdated database and no delicate data has been compromised, as we proceed to observe the very best order of business encryption for our clients. Safety is a excessive precedence focus space which is repeatedly monitored by means of expertise developments and interventions. We guarantee you that we stay 100% dedicated to it. We’re nonetheless investigating and might’t affirm or deny an SQL vulnerability.”

BharatMatrimony is part of Matrimony.com based by Murugavel Janakiraman and is listed on the BSE and NSE. Shares closed 4.04% decrease on the NSE at Rs 27.55 on Thursday.

Information from the corporate’s different web property Elitematrimony was additionally a part of the breach, in response to Cyble.

“The risk actor alleged to have exploited a SQL Injection vulnerability on their platform and leveraged that to extract their databases and consumer information. The actor is actively promoting the database in numerous cybercrime boards for as little as $500,” mentioned Beenu Arora, CEO and Founding father of Cyble.

SQL or Structured Question Language is a programming language used for “speaking” to databases. In SQL Injection Assaults, malicious SQL statements are inserted right into a area such that the attackers is ready to steal the web site’s information and have it dumped onto his or her database.

The agency mentioned that the parameter “themeid” was injected onto one of many web site’s URLs.

“We recognized the breach and notified the corporate,” the cybersecurity agency mentioned.

