comscore JustDial breach leaks personal data of more than 100 million users
News

JustDial breach leaks personal data of more than 100 million users

The report revealed that the problematic API endpoint was online since 2015. It is unclear if anyone knew about the security issue prior to this or if the JustDial user data was used previously in any malicious capacity.

  • Published: April 18, 2019 2:03 PM IST
Data breach

Information about a new and massive data breach has surfaced online. According to a report, it looks like JustDial, the local search service has just suffered a huge data breach. Taking a closer look at the incident, personal information of more than 100 million users was exposed in the data breach. This information includes names, mobile numbers, email IDs, gender, date of birth and even their addresses. This breach was initially discovered by Rajshekhar Rajaharia, an independent security researcher who disclosed the issue in a post on his Facebook account. Also Read - Internet turns 25 in India: Here's how the next 25 years may look like

Also Read - Aarogya Setu app now lets users delete account, erase data: Here's how

After Rajaharia posted about the data breach, it was picked up by The Hacker News. According to Rajaharia, 70 percent of the leaked data belonged to users who had used the customer care number of JustDial, 88888 88888 . He revealed that the company was also leaking the images, the company that the users worked at, their occupation and all other details that a JustDial profile typically asks the user to fill up during signup. As part of the Facebook post, Rajaharia revealed that he had tried to get in touch with the technology or the security team for JustDial but to no avail. Also Read - Facebook shares data of inactive users with thousands of developers; can’t seem to learn

Watch: Android Q First Look

According to the report, this information was exposed because of an unprotected, API endpoint that was publicly accessible to anyone and everyone online. Another shocking thing to see here is that the problematic API endpoint was online since 2015. It is unclear if anyone knew about the security issue prior to this or if the JustDial user data was used previously in any malicious capacity. The report also noted that the API could be used to fetch the personal information of newly registered users in real time.

It is worth noting that the offending API endpoint is old and the company is not currently using it. Instead, the company is using a new API endpoint which is protected and comes with authentication measures to protect the user data. Similar to the new API endpoint, the new JustDial website was not suffering from the breach. In addition to this, Rajshekhar was also able to find a few other old API endpoints that were not protected. What is problematic is how all this data can be used for identity theft.

A report by The Economic Times stated that JustDial reached out to Rajaharia regarding the issue but it was unable to fix the issue at the time of writing. It also noted that the company refuted claims about the data breach of about 100 million users in a statement. JustDial clarified that no financial data was ever leaked from the website and stated that the older apps were fixed with encryption. Last but not least, the company has also issued a tech-audit to discover any such hidden issues and fix them.

For the latest tech news across the world, latest PC and Mobile games, tips & tricks, top-notch gadget reviews of most exciting releases follow BGR India’s Facebook, Twitter, subscribe our YouTube Channel.
  • Published Date: April 18, 2019 2:03 PM IST



new arrivals in india

Realme Narzo 20A
Realme Narzo 20A

8,499

Realme Narzo 20
Realme Narzo 20

10,499

Realme Narzo 20 Pro
Realme Narzo 20 Pro

14,999

Oppo F17
Oppo F17

17,990

Samsung Galaxy M51
Samsung Galaxy M51

24,999

Poco M2
Poco M2

10,999

Oppo F17 Pro
Oppo F17 Pro

22,990

Realme 7 Pro
Realme 7 Pro

19,999

Realme 7
Realme 7

14,999

Xiaomi Redmi 9A
Xiaomi Redmi 9A

6,799

Vivo Y20
Vivo Y20

12,990

Xiaomi Redmi 9
Xiaomi Redmi 9

8,999

Nokia 5.3
Nokia 5.3

13,999

Motorola Moto G9
Motorola Moto G9

11,499

Realme C15
Realme C15

9,999

Realme C12
Realme C12

8,999

Samsung Galaxy Note 20
Samsung Galaxy Note 20

77,999

Xiaomi Redmi 9 Prime
Xiaomi Redmi 9 Prime

9,999

Oppo Reno4 Pro
Oppo Reno4 Pro

34,990

Samsung Galaxy M01 Core
Samsung Galaxy M01 Core

5,499

Realme 6i
Realme 6i

12,999

Asus Rog Phone 3
Asus Rog Phone 3

49,999

OnePlus Nord
OnePlus Nord

24,999

Infinix Smart 4 Plus
Infinix Smart 4 Plus

7,999

Xiaomi Redmi Note 9
Xiaomi Redmi Note 9

11,999

Samsung Galaxy M01s
Samsung Galaxy M01s

9,999

Vivo X50 Pro 5G
Vivo X50 Pro 5G

49,990

Vivo X50 5G
Vivo X50 5G

34,990

Realme C11
Realme C11

7,499

Poco M2 Pro
Poco M2 Pro

13,999

Realme X3
Realme X3

24,999

Realme X3 SuperZoom
Realme X3 SuperZoom

27,999

Tecno Spark Power 2
Tecno Spark Power 2

9,999

Oppo A12
Oppo A12

9,990

Oppo A52
Oppo A52

16,990

Samsung Galaxy A21s
Samsung Galaxy A21s

15,999

Oppo Find X2
Oppo Find X2

64,990

Motorola One Fusion Plus
Motorola One Fusion Plus

17,499

Samsung Galaxy A31
Samsung Galaxy A31

20,999

Samsung Galaxy M01
Samsung Galaxy M01

8,999

Samsung Galaxy M11
Samsung Galaxy M11

10,999

Infinix Hot 9 Pro
Infinix Hot 9 Pro

9,999

LG Velvet
LG Velvet

Price Not Available

Xiaomi Mi Note 10 Lite
Xiaomi Mi Note 10 Lite

Price Not Available

Apple iPhone SE 2020
Apple iPhone SE 2020

42,500

Honor 30 Pro
Honor 30 Pro

Price Not Available

Honor 30
Honor 30

Price Not Available

OnePlus 8
OnePlus 8

44,999

OnePlus 8 Pro
OnePlus 8 Pro

54,999

Xiaomi Redmi Note 9 Pro
Xiaomi Redmi Note 9 Pro

13,999

Motorola Moto E4
Motorola Moto E4

8,999

Samsung Galaxy On Max
Samsung Galaxy On Max

9,775

nubia N2
nubia N2

15,999

Karbonn K9 Kavach 4G
Karbonn K9 Kavach 4G

5,290

Motorola Moto C Plus
Motorola Moto C Plus

6,999

Best Sellers