IRCTC May Have 2 Lakh Passengers' Data Exposed To Hackers For Almost 2 Years
Indira Datta
The IRCTC site is thought to have a vulnerability that could allow hackers to steal data of passengers.
- 3.2 Billion Email And Password Pairs Have Been Leaked, Here's How To Check If You Are Affected
- Company Uses Smart Seat Cushions For Staff Monitoring
- IBM And Fujifilm Team Up To Create Magnetic Tape With World-Record 580TB Storage
IRCTC is a mobile application that connects to third-party insurers for free travel insurance. IRCTC introduced the service in December last year. The IRCTC site is thought to have a vulnerability that could allow hackers to steal data of passengers.
According to ET, IRCTC has announced that they have fixed a huge security bug after nearly two years of loose. In particular, the bug may have exposed at least 2,00,000 (2 lakh) passengers and allowed attackers to approach their details, though it's not clear if hackers did access to the data or not.
Free travel insurance is compulsory for those who buy tickets through the IRCTC's site or phone app. Accordingly, the information of these travel insurance applicants will be forwarded to a third insurance company in cooperation with the IRCTC to ensure customers in accordance with regulations.
Earlier on August 14th, network security researcher Avinash Jain discovered and reported the bug to the company. Then on the 29th of the same month, the IRCTC learned and corrected the error.
Jain responded to the ET reporter that in just 10 minutes, he was able to read personal information as well as the schedule of nearly 1,000 passengers and candidates.
Meanwhile, the site handles around 6,00,000 (6 lakh) tickets each day. So Jain can calculate at least 2,00,000 (2 lakh) of passenger information and the details of the ticket holder are public because one of the three insurance companies can enter.
Gurunatha Reddy Gopireddy, who co-research Jain on seeking for the flaw, told ET:
Obviously, Royal Sundaram General Insurance and ICICI Lombard General Insurance are the two remaining insurance companies without the fault. Funny, IRCTC announced that they had fixed the bug on August 29, but the company has stopped compelling customers to join the free travel insurance service from September 1, you can now choose whether to opt for travel insurance when booking on IRCTC.
Featured Stories
ICT News - Apr 13, 2026
DDR4 RAM Prices Finally Fall After Soaring More Than 2,200 Percent
ICT News - Apr 06, 2026
Artemis II Crew Enters Moon's Gravitational Sphere on Historic Day 5
ICT News - Mar 31, 2026
DDR5 RAM Prices Finally Easing: Relief for PC Builders in 2026
ICT News - Mar 29, 2026
FTC Takes Action Against Debanking Practices by Major Financial Firms
ICT News - Mar 27, 2026
Palantir CTO Identifies Iran Conflict as First Large-Scale AI-Driven War
ICT News - Mar 24, 2026
OpenAI on the Brink: Major Setbacks Signal the Bursting of the AI Bubble
ICT News - Mar 20, 2026
Top 10 Most Popular Social Media Sites Based on User Count in 2026
ICT News - Mar 19, 2026
Billion Dollar Blunder: Meta Shuts Down Metaverse After Wasting $80,000,000,000.00
ICT News - Mar 18, 2026
X to Introduce Regional Controls for Posts and Replies
ICT News - Mar 17, 2026
Is DLSS 5 Helping Games or Hurting Developers' Creative Style?
Read More
Mobile- Apr 21, 2026
Huawei Mate X7 Review: Foldable Photography Without Compromises
Huawei has built its Mate X series around one core promise: deliver premium experiences in a folding form factor without the usual trade-offs.
Mobile- Apr 19, 2026
Samsung Cuts Galaxy S26 Series Prices by Up to ₹19,000 in India
If you are planning to upgrade, this is a good time to check the latest offers on your preferred model.