BigBasket’s database has reportedly been listed on the dark web. This work has been done by a hacking group named ShinyHunters. The database, which is listed online, contains important information such as email addresses, names, dates of birth and phone numbers of users.
Infamous threat actor “ShinyHunters” just leaked the database of “BigBasket, a famous Indian ???????? online grocery delivery service. (@bigbasket_com,
20,000,000+ clients affected and information such as emails, names, hashed passwords, birthdates and phone numbers were leaked. pic.twitter.com/tD5TMxNkH7
— Alon Gal (Under the Breach) (@UnderTheBreach) April 25, 2021
Cyber-security researcher Rajshekhar Rajaharia told Gadgets 360 that the leaked database is linked to a breach that BigBasket itself confirmed in November last year.
ShinyHunters made the alleged BigBasket database available for download on the dark web over the past weekend. This includes the hashed passwords of the affected customers. However, it is reported that some passwords in plain text have now been put to sell on the dark web.
Meanwhile, the website “Have I Been Pwned?” providing users with information about the leak of their data? has also sent emails informing some of the affected users about the data leak.
You can check whether your information is in this database or not, through Have i Been Pwned. You have to enter your email id or mobile number registered with BigBasket inside the box on home and click on ‘pwned’ button. This website will display the details of all agreements entered into with the e-mail address you entered.