Ambimat GroupAmbimatAmbiSecureSIMAuthAmbiAutomationEngineering BlogAhmedabad · India · Est. 1982
HISTORICAL ARCHIVE · Originally published August 5, 2021
Archive

Cyber Attacks in India: Incident Response & Lessons (Part 3)

Part three of a three-part analysis of major cyber attacks in India — closing the series with systemic gaps in incident response, identity hygiene, and hardware-rooted authentication adoption.

This is an earlier piece from the AmbiSecure engineering archive. Where the field has moved on, the link above points to current coverage of the same topic.

Part three closes a three-part analysis of major cyber attacks against Indian institutions (continuing from Part 1 and Part 2). What stays consistent across every incident is the authentication weakness behind it.

AmbiSecure aims to protect connected environments against cybercrime. Ambimat Electronics, with over forty years of experience, introduces the OnePass USB Key product.

Major Breaches Documented

Juspay Data Breach

Approximately 35 million customer accounts were compromised in August through an unrecycled access key. Details including masked card data and fingerprints were offered for sale on the dark web for around $5,000.

BigBasket Breach

Nearly 20 million users' personal information from the online grocery platform was listed for ₹3 million. Exposed data included "names, email IDs, password hashes, PINs, mobile numbers, addresses, dates of birth, locations, and IP addresses." Discovery occurred October 30; BigBasket was notified November 1.

Unacademy Compromise

The edutech startup disclosed that 22 million user accounts were compromised, with usernames, emails, and passwords exposed on the dark web.

Healthcare Records Theft

FireEye reported that hackers linked to the Chinese group Fallensky519 stole information on 68 lakh patients and doctors, with records offered below $2,000.

JustDial Exposure

Over 100 million users' data became publicly available, including names, email addresses, mobile numbers, gender, birthdate, and addresses.

About AmbiSecure

AmbiSecure supports FIDO2 protocol implementation, enabling passwordless authentication. The technology requires no battery or network connectivity.

Who is Ambimat Electronics?

Nearly four decades of design experience serving PSUs, private companies, and startups across multiple sectors including IoT, smartwatches, smart homes, medical devices, robotics, retail, and security.

Frequently asked questions

Which breaches does part 3 cover?

It closes the series with the Juspay breach and the BigBasket breach, then draws out the systemic gaps in incident response and identity hygiene.

What caused the Juspay breach?

An unrecycled access key. Roughly 35 million customer accounts were affected, and masked card data was offered on the dark web for around $5,000.

What is the common lesson across all three parts?

Every incident traces back to an authentication weakness. The durable mitigation is hardware-rooted: attested keys, on-device biometrics and signed firmware.

What was the BigBasket breach?

Personal information for nearly 20 million users of the online grocery platform was listed for sale at around ₹3 million.

What would have limited the damage in these cases?

Credentials that cannot be replayed once stolen. Hardware-bound keys, attested devices and signed firmware remove the value of the exact artefacts these attackers exfiltrated and resold.

Browse more historical AmbiSecure writing.

The full archive lists everything we have published, with the modern-equivalent counterpart linked wherever one exists.

Open archive