IRCTC May Have 2 Lakh Passengers' Data Exposed To Hackers For Almost 2 Years
Indira Datta - Nov 13, 2018
The IRCTC site is thought to have a vulnerability that could allow hackers to steal data of passengers.
- 3.2 Billion Email And Password Pairs Have Been Leaked, Here's How To Check If You Are Affected
- Company Uses Smart Seat Cushions For Staff Monitoring
- IBM And Fujifilm Team Up To Create Magnetic Tape With World-Record 580TB Storage
IRCTC is a mobile application that connects to third-party insurers for free travel insurance. IRCTC introduced the service in December last year. The IRCTC site is thought to have a vulnerability that could allow hackers to steal data of passengers.

According to ET, IRCTC has announced that they have fixed a huge security bug after nearly two years of loose. In particular, the bug may have exposed at least 2,00,000 (2 lakh) passengers and allowed attackers to approach their details, though it's not clear if hackers did access to the data or not.
Free travel insurance is compulsory for those who buy tickets through the IRCTC's site or phone app. Accordingly, the information of these travel insurance applicants will be forwarded to a third insurance company in cooperation with the IRCTC to ensure customers in accordance with regulations.
Earlier on August 14th, network security researcher Avinash Jain discovered and reported the bug to the company. Then on the 29th of the same month, the IRCTC learned and corrected the error.
Jain responded to the ET reporter that in just 10 minutes, he was able to read personal information as well as the schedule of nearly 1,000 passengers and candidates.

Meanwhile, the site handles around 6,00,000 (6 lakh) tickets each day. So Jain can calculate at least 2,00,000 (2 lakh) of passenger information and the details of the ticket holder are public because one of the three insurance companies can enter.
Gurunatha Reddy Gopireddy, who co-research Jain on seeking for the flaw, told ET:

Obviously, Royal Sundaram General Insurance and ICICI Lombard General Insurance are the two remaining insurance companies without the fault. Funny, IRCTC announced that they had fixed the bug on August 29, but the company has stopped compelling customers to join the free travel insurance service from September 1, you can now choose whether to opt for travel insurance when booking on IRCTC.
Featured Stories
ICT News - Feb 20, 2026
Tech Leaders Question AI Agents' Value: Human Labor Remains More Affordable
ICT News - Feb 19, 2026
Escalating Costs for NVIDIA RTX 50 Series GPUs: RTX 5090 Tops $5,000, RTX 5060 Ti...
ICT News - Feb 18, 2026
Google's Project Toscana: Elevating Pixel Face Unlock to Rival Apple's Face ID
Mobile - Feb 16, 2026
Xiaomi Launches Affordable Tracker to Compete with Apple's AirTag
ICT News - Feb 15, 2026
X Platform Poised to Introduce In-App Crypto and Stock Trading Soon
ICT News - Feb 13, 2026
Elon Musk Pivots: SpaceX Prioritizes Lunar Metropolis Over Martian Colony
ICT News - Feb 10, 2026
Discord's Teen Safety Sham: Why This Data Leak Magnet Isn't Worth Your Trust...
ICT News - Feb 09, 2026
PS6 Rumors: Game-Changing Specs Poised to Transform Console Play
ICT News - Feb 08, 2026
Is Elon Musk on the Path to Becoming the World's First Trillionaire?
ICT News - Feb 07, 2026
NVIDIA's Gaming GPU Drought: No New Releases in 2026 as AI Takes Priority
Read more
ICT News- Feb 18, 2026
Google's Project Toscana: Elevating Pixel Face Unlock to Rival Apple's Face ID
As the smartphone landscape evolves, Google's push toward superior face unlock technology underscores its ambition to close the gap with Apple in user security and convenience.
ICT News- Feb 19, 2026
Escalating Costs for NVIDIA RTX 50 Series GPUs: RTX 5090 Tops $5,000, RTX 5060 Ti Closes in on RTX 5070 Pricing
As the RTX 50 series continues to push boundaries in gaming and AI, these price trends raise questions about accessibility for average gamers.
ICT News- Feb 20, 2026
Tech Leaders Question AI Agents' Value: Human Labor Remains More Affordable
In a recent episode of the All-In podcast, prominent tech investors and entrepreneurs expressed skepticism about the immediate practicality of deploying AI agents in business operations.
Comments
Sort by Newest | Popular