When personal data is put on the internet for convenience of access, it should be secured. Otherwise, a catastrophe awaits.
This was experienced by the ticketing platform RailYatri.
The Indian company inadvertently exposed the personal information of its more than 700,000 users due to an unsecured server.
The exposed server was discovered by a team of researchers led by Anurag Sen at a a cybersecurity company called Safety Detectives. Sen and his team found the unsecured RailYatri database on an Easticsearch server on August 10.
In a blog post, the team said that the database was 43GB in size, and had a comprehensive details about travelers, as well as location information of users that were gathered through live tracking of trains.
However, on August 12, a Meow attack destroyed most of the data, reducing its size significantly to just 1GB.

The complete information that leaked due to the unsecured database, include:
- Full names.
- Age.
- Gender.
- Physical addresses.
- Email addresses.
- Mobile phone numbers.
- Payment logs.
- Partial records of credit and debit card information.
- Unified Payment Interface (UPI) ID.
- Train and bus ticket booking details.
- Travel itinerary information including which stations passengers boarded/disembarked.
- Users’ GPS location information including MCC, MNC, LAC and CellID data:
- MCC: mobile country code to identify country.
- MNC: mobile network code to identify mobile operator.
- LAC: location area code to identify pockets of base stations.
- CellID: unique number to identify each base transceiver station or sector.
- Authentication token information.
- User session logs including login times.

The team at Safety Detectives contacted RailTatri as soon as practically possible..
But because the company couldn't be reached, the team contacted India’s Computer emergency response team (CERT-In), a government agency responsible for national cybersecurity, to make them aware of the issue on August 17.
Later, access to the database was silently closed without any confirmation from CERT-In or RailTatri.
The Indian railway network is one of the busiest transportation systems in the world, as it serves more than 24 million passengers every single day.
RailYatri here, is considered as one of India’s most popular travel booking hubs, which conducts its primary business by offering those people the ticketing booking service, as well as train information.
Just like most database breaches, information that went public can reveal a lot about a person whose information is available inside the databse.
In this case, RailYatri’s exposed database can be used by attackers or other malicious actors to create targeted hacks. And because the database also contained location and travel data, there’s an issue of physical safety as well.























































































































































































































































































































































































