logo

Inside the BWSSB Incident : How An Exposed Environment File Enabled the Sale of 290K+ Applicant Records and Database Root Access

ID: 0e745db4-e7b6-5de6-ae5b-26262161b3d6

STIX ID: report--0e745db4-e7b6-5de6-ae5b-26262161b3d6

Feed Name: CloudSEK Blog

Threat Score
78/100

Date Published: 2025-04-29

Date Updated: 2026-04-27

...
...

**Executive Summary:** CloudSEK's STRIKE Team investigated a breach of the Bangalore Water Supply and Sewerage Board (BWSSB) in which a threat actor 'pirates_gold' advertised direct root access and a data dump of ~291,212 user records for sale. Reconnaissance identified an exposed Adminer management interface and a publicly accessible .env file containing valid plaintext MySQL credentials that enabled full database access; the exposed credentials were later disabled though the actor claims persistent access. The compromised dataset reportedly contains extensive PII (names, phone numbers, addresses, emails, Aadhaar) and multiple sensitive tables, posing elevated risk of data abuse, targeted phishing, manipulation of operational data, and disruption of services.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.