A customer data leak from BigBasket is indexed on leaksear.ch with 15,695,000 records tied to an October 14, 2020 breach (leaksear.ch metadata). BigBasket is an Indian online grocery delivery service, and public reporting and Have I Been Pwned described the broader incident as exposing more than 20 million customer records that were sold before being leaked publicly in April 2021 (haveibeenpwned.com, bleepingcomputer.com).
What happened
leaksear.ch metadata identifies the indexed source as a MySQL dump of BigBasket's member_member table (leaksear.ch metadata). India Today reported that Cyble found a BigBasket database portion with the same table name for sale in a cybercrime market for more than $40,000, and that BigBasket acknowledged the breach and filed a police complaint (indiatoday.in).
On April 25, 2021, BleepingComputer and TechCrunch reported that ShinyHunters posted the alleged BigBasket database for free on a hacking forum (bleepingcomputer.com, techcrunch.com). The public reports reviewed here do not establish a confirmed initial access method.
BigBasket said financial data was not stored and that credit card details were not part of the breach, while a later company statement to TechCrunch said the April 2021 publication referred to the 2020 incident rather than a new breach (moneycontrol.com, techcrunch.com).
What data was exposed
The leaksear.ch index lists names, email addresses, phone numbers, physical addresses, dates of birth, IP addresses and SHA1 hashed passwords in the exposed records (leaksear.ch metadata). Have I Been Pwned lists the compromised data as dates of birth, email addresses, IP addresses, names, passwords, phone numbers and physical addresses, and describes the passwords as Django(SHA-1) hashes (haveibeenpwned.com).
Why this matters
The combination of email addresses, phone numbers, physical addresses and dates of birth can support convincing delivery-themed phishing, account-recovery abuse and identity-fraud attempts. SHA1 hashed passwords do not disclose plaintext by themselves, but weak or reused passwords can become useful to attackers if cracked or matched against other breach data. Because BigBasket publicly said it did not store financial data, the main confirmed exposure centers on account credentials and personal contact details rather than payment-card numbers (moneycontrol.com). If you used BigBasket around 2020, check whether your data is in this leak and reset any reused passwords immediately.
Check your exposure
Vetted researchers and incident-response teams can request access or sign in if they already have access to check this dataset. Searchable pivots for this leak include address, date of birth, email, hashed password, ip address, name, and phone.
Sources
- Have I Been Pwned: bigbasket Data Breach
- BleepingComputer: Hacker leaks 20 million alleged BigBasket user records for free
- TechCrunch: Alleged records of 20 million BigBasket users published online
- India Today: BigBasket confirms data breach of 2 crore BB users, here is what we know so far
- Moneycontrol: Bigbasket confident that financial data of customers secure