Ambimat GroupAmbimatAmbiSecureSIMAuthAmbiAutomationEngineering BlogAhmedabad · India · Est. 1982
HISTORICAL ARCHIVE · Originally published July 28, 2021
Archive

Cyber Attacks in India: Attack Patterns (Part 2)

Part two of a three-part analysis of major cyber attacks in India — the attack patterns, the identity weaknesses they exploited, and what enterprise authentication posture would have stopped them.

This is an earlier piece from the AmbiSecure engineering archive. Where the field has moved on, the link above points to current coverage of the same topic.

Part two of a three-part analysis of major cyber attacks in India continues from Part 1. The pattern across these incidents is consistent: credential theft, weak second factors, and unhardened privileged access. AmbiSecure aims to protect connected systems against cybercrime.

Major Breaches Detailed

SBI Data Breach

State Bank of India's unsecured server exposed "three million text messages sent to customers" through SBI Quick, revealing account balances and recent transactions.

Domino's India Incident

A hacker offered 13 TB of data including "180 million Domino's India pizza orders" along with customer names, phone numbers, and email addresses for 10 bitcoin. Jubilant Food Works acknowledged the breach but stated customer financial information wasn't compromised.

Upstox Trading Platform

The platform reset passwords after a breach report involving "know-your-customer (KYC) data" held in a third-party warehouse.

Police Exam Database

"Personally identifiable information of 500,000 Indian police personnel was put up for sale" containing names, mobile numbers, email IDs, birth dates, FIR records, and criminal histories.

COVID-19 Test Results

Patient test results became publicly accessible through Google indexing, showing names, birth dates, testing dates, and testing centers from government websites.

Who is AmbiSecure?

AmbiSecure provides FIDO2 protocol support for password-less authentication, offering hardware-based security without requiring batteries or network connectivity.

Frequently asked questions

Which breaches does part 2 examine?

It details the State Bank of India SMS data exposure through the SBI Quick service and the Domino's India breach, among other incidents in the same period.

What pattern connects these attacks?

The same three weaknesses recur across every incident: credential theft, weak second factors, and unhardened privileged access.

How much data was involved in the Domino's India breach?

A hacker offered 13 TB of data covering around 180 million Domino's India pizza orders, including customer names, phone numbers and email addresses. Jubilant FoodWorks acknowledged the breach but said financial information was not compromised.

What was exposed in the State Bank of India incident?

An unsecured server behind the SBI Quick service exposed around three million text messages sent to customers, revealing account balances and recent transactions.

Why does this series keep returning to authentication rather than perimeter security?

Because in each incident the attacker arrived with valid access — a stolen credential, a weak second factor, or an unhardened privileged account. A perimeter control never had the chance to make the decision.

Browse more historical AmbiSecure writing.

The full archive lists everything we have published, with the modern-equivalent counterpart linked wherever one exists.

Open archive