{"id":1210,"date":"2021-05-22T17:47:47","date_gmt":"2021-05-22T16:47:47","guid":{"rendered":"https:\/\/zerothcode.com\/blog\/?p=1210"},"modified":"2021-05-22T17:47:47","modified_gmt":"2021-05-22T16:47:47","slug":"dominos-data-leak-18-cr-indian-customer-orders-resurfaces-customer","status":"publish","type":"post","link":"https:\/\/zerothcode.com\/blog\/dominos-data-leak-18-cr-indian-customer-orders-resurfaces-customer\/","title":{"rendered":"Domino\u2019s India Data Leak Of 18 Cr Orders Resurfaces; Customer Location, Mobile Numbers Exposed"},"content":{"rendered":"<p>domino&#8217;s data leak Data related to over 18 Cr orders from pizza chain Domino\u2019s India appeared on the dark web last month<\/p>\n<p>Now, it has been put up on the dark web as a search engine of sorts, allowing hackers to track and trace users down to their visited locations<\/p>\n<h4>domino&#8217;s data leak The data includes names, email addresses, mobile numbers, GPS coordinates, and more related to Domino\u2019s pizza orders<\/h4>\n<p>After data related to over 18 Cr orders from the pizza chain, Domino\u2019s India appeared on the dark web last month, now the same database has been made public by the hacker or hacking group.<\/p>\n<p>The data has been put up on the dark web as a searchable database allowing hackers to track and trace users down to their visited locations. domino&#8217;s data leak<\/p>\n<p>Last month, a\u00a0threat actor claimed to have stolen 13 TB of data from Domino\u2019s India, putting the personal information of 250 employees across functions and customer details from 18 Cr orders.<\/p>\n<p>Now, this data has been put up on a search engine of sorts, according to cybersecurity researcher Rajshekhar Rajaharia. He further added that this includes names, email addresses, mobile numbers, GPS coordinates, and more related to Domino\u2019s orders.<\/p>\n<p>In a screenshot posted on Twitter, one can see that the data can be used to create a map of a user\u2019s visited locations by matching the phone number to the GPS location data.<\/p>\n<p>\u201cThe worst part of this alleged breach is that people are using this data to spy on people. Anyone can easily search any mobile number and check a person\u2019s past locations with date and time. This seems like a real threat to our privacy,\u201d Rajaharia said.<\/p>\n<figure id=\"attachment_251809\" class=\"wp-caption aligncenter\" aria-describedby=\"caption-attachment-251809\">\n<p><figure id=\"attachment_251809\" aria-describedby=\"caption-attachment-251809\" style=\"width: 640px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"jetpack-lazy-image jetpack-lazy-image--handled wp-image-251809 size-large\" src=\"https:\/\/inc42.com\/wp-content\/uploads\/2021\/05\/domi-1024x576.jpg\" sizes=\"auto, (max-width: 640px) 100vw, 640px\" srcset=\"https:\/\/inc42.com\/wp-content\/uploads\/2021\/05\/domi-1024x576.jpg 1024w, https:\/\/inc42.com\/wp-content\/uploads\/2021\/05\/domi-300x169.jpg 300w, https:\/\/inc42.com\/wp-content\/uploads\/2021\/05\/domi-1536x864.jpg 1536w, https:\/\/inc42.com\/wp-content\/uploads\/2021\/05\/domi-1250x703.jpg 1250w, https:\/\/inc42.com\/wp-content\/uploads\/2021\/05\/domi-400x225.jpg 400w, https:\/\/inc42.com\/wp-content\/uploads\/2021\/05\/domi-210x118.jpg 210w, https:\/\/inc42.com\/wp-content\/uploads\/2021\/05\/domi-690x388.jpg 690w, https:\/\/inc42.com\/wp-content\/uploads\/2021\/05\/domi.jpg 1726w\" alt=\"domino's data leak\" width=\"640\" height=\"360\" data-lazy-loaded=\"1\" \/><figcaption id=\"caption-attachment-251809\" class=\"wp-caption-text\">domino&#8217;s data leak<\/figcaption><\/figure><figcaption id=\"caption-attachment-251809\" class=\"wp-caption-text\">The leaked data from Domino\u2019s India<\/figcaption><\/figure>\n<p>News about the data leak was shared last month on\u00a0Twitter by Alon Gal, co-founder, and CTO of cybercrime intelligence firm Hudson Rock.<\/p>\n<p>The database was being sold on the dark web for around two to eight bitcoins, with a 50 bitcoin ransom for the company to block the sale of its data.<\/p>\n<h4>The database includes personal details of the customers provided to Domino\u2019s India when they placed an order through its website or app.<\/h4>\n<h4>These include names, phone numbers, email IDs, addresses, and payment card details.<\/h4>\n<p>However, the hacker has denied sharing any sample of the stolen data with cybersecurity researchers, which means that claims about the stolen data, size, and contents are just allegations.<\/p>\n<p>According to screenshots of the leaked database shared by Gal on Twitter, the data stolen from Domino\u2019s India\u2019s database is from the period between 2015-21, although this remains unverified.<\/p>\n<h5>Responding to the data breach allegations last month, a Domino\u2019s India spokesperson told <b><i>Inc42<\/i><\/b>\u00a0that while the company had detected an \u2018information security\u2019 incident recently,<\/h5>\n<h5>no financial information of users had been compromised.<\/h5>\n<div class=\"code-block code-block-94\">\n<div class=\"also-read\">\u201cThe incident has not resulted in any operational or business impact.<\/div>\n<\/div>\n<p>As a policy we do not store financial details or credit card data of our customers, thus no such information has been compromised.<\/p>\n<p>Our team of experts is investigating the matter and we have taken the necessary actions to contain the incident,\u201d the spokesperson had said at the time.<\/p>\n<div class=\"code-block code-block-29\">\n<div id=\"inc42_article_middle-0\" class=\"text-center inc42-middle ad-container ad-container-in-content ad-block\"><\/div>\n<\/div>\n<p>The company did not respond to questions about the severity of the customer location and phone numbers data being leaked.<\/p>\n<h3><b>Hackers Target Indian Startups<br \/>\n<\/b><\/h3>\n<p>A report by IBM\u2019s \u2018Cost of a Data Breach Report 2020\u2019 states that Indian companies witnessed an average $2 Mn total cost of a data breach in 2020, representing an increase of 9.4% from 2019.<\/p>\n<p>A total of over 26,100 Indian websites were hacked in 2020 amid the pandemic as per the data recorded by the state-owned Indian Computer Emergency Response Team (CERT-In).<\/p>\n<p>In March, Network18-owned finance portal\u00a0MoneyControl also suffered an alleged data breach, one that supposedly affected 7 lakh users. Days before, online discount broking platform\u00a0Upstox suffered a data breach that allegedly affected 2.5 Mn users.<\/p>\n<p>And last month,\u00a0fintech startup Mobikwik denied claims\u00a0about a data breach impacting 100 Mn users, despite proof of the data belonging to Mobikwik users.<\/p>\n<p>In February, the Reserve Bank of India (RBI), alarmed by the state of data breaches affecting Indian startups and payments processors, issued new guidelines that stated that payment aggregators and gateways would not be allowed to store the card details of a customer online.<\/p>\n<p>The decision came a few weeks after a data breach affecting payments processor Juspay\u00a0led to over 10 Cr user records being leaked online.<\/p>\n<p>As of now, no action has been taken against any of these platforms for not keeping customer data safe.<\/p>\n<p>In a hyper-connected world with tech platforms often having an overlap of users, such data leaks have a cascading impact on the entire ecosystem.<\/p>\n<p>In November last year, BigBasket has faced a data breach that exposed the personal details of around 2 Cr users. The data was put up for sale for around INR 30 Lakh and in\u00a0April this year,<\/p>\n<p>the data was leaked online in a similar manner to how the Domino\u2019s India database has been leaked.<\/p>\n<p>Since then, many users who have been impacted by the BigBasket leak have complained that their Flipkart accounts have been hijacked.<\/p>\n<p>The problem here could potentially extend beyond Flipkart.<\/p>\n<p>Because in this case, it is not Flipkart\u2019s data that has been leaked but rather passwords and usernames belonging to BigBasket users, who also have accounts on Flipkart.<\/p>\n<p>Many of these users are likely to have used the credentials they used for BigBasket for other platforms.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>domino&#8217;s data leak Data related to over 18 Cr orders from pizza chain Domino\u2019s India appeared on the dark web<\/p>\n","protected":false},"author":1,"featured_media":1211,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[37],"tags":[],"yst_prominent_words":[],"class_list":["post-1210","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-hackers-news"],"_links":{"self":[{"href":"https:\/\/zerothcode.com\/blog\/wp-json\/wp\/v2\/posts\/1210","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/zerothcode.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/zerothcode.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/zerothcode.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/zerothcode.com\/blog\/wp-json\/wp\/v2\/comments?post=1210"}],"version-history":[{"count":0,"href":"https:\/\/zerothcode.com\/blog\/wp-json\/wp\/v2\/posts\/1210\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/zerothcode.com\/blog\/wp-json\/wp\/v2\/media\/1211"}],"wp:attachment":[{"href":"https:\/\/zerothcode.com\/blog\/wp-json\/wp\/v2\/media?parent=1210"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/zerothcode.com\/blog\/wp-json\/wp\/v2\/categories?post=1210"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/zerothcode.com\/blog\/wp-json\/wp\/v2\/tags?post=1210"},{"taxonomy":"yst_prominent_words","embeddable":true,"href":"https:\/\/zerothcode.com\/blog\/wp-json\/wp\/v2\/yst_prominent_words?post=1210"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}