Inside the BWSSB Incident : How An Exposed Environment File Enabled the Sale of 290K+ Applicant Records and Database Root Access
ID: 0e745db4-e7b6-5de6-ae5b-26262161b3d6
STIX ID: report--0e745db4-e7b6-5de6-ae5b-26262161b3d6
Feed Name: CloudSEK Blog
**Executive Summary:** CloudSEK's STRIKE Team investigated a breach of the Bangalore Water Supply and Sewerage Board (BWSSB) in which a threat actor 'pirates_gold' advertised direct root access and a data dump of ~291,212 user records for sale. Reconnaissance identified an exposed Adminer management interface and a publicly accessible .env file containing valid plaintext MySQL credentials that enabled full database access; the exposed credentials were later disabled though the actor claims persistent access. The compromised dataset reportedly contains extensive PII (names, phone numbers, addresses, emails, Aadhaar) and multiple sensitive tables, posing elevated risk of data abuse, targeted phishing, manipulation of operational data, and disruption of services.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
