IRCTC May Have 2 Lakh Passengers' Data Exposed To Hackers For Almost 2 Years
Indira Datta - Nov 13, 2018
The IRCTC site is thought to have a vulnerability that could allow hackers to steal data of passengers.
- 3.2 Billion Email And Password Pairs Have Been Leaked, Here's How To Check If You Are Affected
- Company Uses Smart Seat Cushions For Staff Monitoring
- IBM And Fujifilm Team Up To Create Magnetic Tape With World-Record 580TB Storage
IRCTC is a mobile application that connects to third-party insurers for free travel insurance. IRCTC introduced the service in December last year. The IRCTC site is thought to have a vulnerability that could allow hackers to steal data of passengers.

According to ET, IRCTC has announced that they have fixed a huge security bug after nearly two years of loose. In particular, the bug may have exposed at least 2,00,000 (2 lakh) passengers and allowed attackers to approach their details, though it's not clear if hackers did access to the data or not.
Free travel insurance is compulsory for those who buy tickets through the IRCTC's site or phone app. Accordingly, the information of these travel insurance applicants will be forwarded to a third insurance company in cooperation with the IRCTC to ensure customers in accordance with regulations.
Earlier on August 14th, network security researcher Avinash Jain discovered and reported the bug to the company. Then on the 29th of the same month, the IRCTC learned and corrected the error.
Jain responded to the ET reporter that in just 10 minutes, he was able to read personal information as well as the schedule of nearly 1,000 passengers and candidates.

Meanwhile, the site handles around 6,00,000 (6 lakh) tickets each day. So Jain can calculate at least 2,00,000 (2 lakh) of passenger information and the details of the ticket holder are public because one of the three insurance companies can enter.
Gurunatha Reddy Gopireddy, who co-research Jain on seeking for the flaw, told ET:

Obviously, Royal Sundaram General Insurance and ICICI Lombard General Insurance are the two remaining insurance companies without the fault. Funny, IRCTC announced that they had fixed the bug on August 29, but the company has stopped compelling customers to join the free travel insurance service from September 1, you can now choose whether to opt for travel insurance when booking on IRCTC.
Featured Stories
ICT News - Mar 05, 2026
X Platform Implements Strict Measures Against Fake AI-Generated Videos Amid Iran...
How To - Mar 04, 2026
Getting Started with AI: A Newbie's Simple Guide
ICT News - Mar 03, 2026
Budget Entry-Level PCs Under $500 to Vanish by 2028 Due to Memory Price Surge
ICT News - Mar 02, 2026
IDC Report Predicts Surging Smartphone Prices Due to Global RAM Shortage
ICT News - Mar 01, 2026
Samsung Links Galaxy S26 Price Hikes to AI Memory Supply Issues
ICT News - Feb 28, 2026
Anthropic Blacklisted by US Department of War: Trump Orders Federal Ban Over AI...
ICT News - Feb 26, 2026
AI Models Frequently Resort to Nuclear Escalation in Simulated Crises, Study...
ICT News - Feb 23, 2026
It's Over for Xbox: Asha Sharma Takes Over to Ruin Microsoft Gaming with AI
ICT News - Feb 22, 2026
Which AI Model Excels at Which Task in 2026: A Comprehensive Guide
ICT News - Feb 21, 2026
AI Coding Agent Causes Major AWS Outage at Amazon
Read more
Mobile- Mar 11, 2026
Top 5 5G Smartphones Under ₹20,000 to Buy in March 2026
These recommendations are based on current market availability in India as of March 2026. Always check for the latest deals on platforms like Amazon or Flipkart.
Comments
Sort by Newest | Popular