Ambimat GroupAmbimatAmbiSecureeSIM InitiativeEngineering BlogAhmedabad · India · Est. 1981
HISTORICAL ARCHIVE · Originally published August 5, 2021
Archive

Cyber Attacks in India – Part 3

Part three of a three-part analysis of major cyber attacks in India — closing the series with systemic gaps in incident response, identity hygiene, and hardware-rooted authentication adoption.

This is an earlier piece from the AmbiSecure engineering archive. Where the field has moved on, the link above points to current coverage of the same topic.

Part three closes a three-part analysis of major cyber attacks against Indian institutions (continuing from Part 1 and Part 2). What stays consistent across every incident is the authentication weakness behind it.

AmbiSecure aims to protect connected environments against cybercrime. Ambimat Electronics, with over forty years of experience, introduces the AmbiSecure key product.

Major Breaches Documented

Juspay Data Breach

Approximately 35 million customer accounts were compromised in August through an unrecycled access key. Details including masked card data and fingerprints were offered for sale on the dark web for around $5,000.

BigBasket Breach

Nearly 20 million users' personal information from the online grocery platform was listed for ₹3 million. Exposed data included "names, email IDs, password hashes, PINs, mobile numbers, addresses, dates of birth, locations, and IP addresses." Discovery occurred October 30; BigBasket was notified November 1.

Unacademy Compromise

The edutech startup disclosed that 22 million user accounts were compromised, with usernames, emails, and passwords exposed on the dark web.

Healthcare Records Theft

FireEye reported that hackers linked to the Chinese group Fallensky519 stole information on 68 lakh patients and doctors, with records offered below $2,000.

JustDial Exposure

Over 100 million users' data became publicly available, including names, email addresses, mobile numbers, gender, birthdate, and addresses.

About AmbiSecure

AmbiSecure supports FIDO2 protocol implementation, enabling passwordless authentication. The technology requires no battery or network connectivity.

About Ambimat Electronics

Nearly four decades of design experience serving PSUs, private companies, and startups across multiple sectors including IoT, smartwatches, smart homes, medical devices, robotics, retail, and security.

Browse more historical AmbiSecure writing.

The full archive lists everything we have published, with the modern-equivalent counterpart linked wherever one exists.

Open archive