Bharat Sanchar Nigam Limited Details

    Organization Logo

    Bharat Sanchar Nigam Limited

    57859 employees • Telecommunications

    India

    Industry

    Telecommunications

    Security Incidents

    1

    Bharat Sanchar Nigam Limited is an Indian central public sector undertaking under the ownership of Department of Telecommunications, which is part of the Ministry of Communications, Government of India with its headquarters in New Delhi, India.

    Security Incidents

    Bharat Sanchar Nigam Limited Breach of May 2024
    Severity Score
    Significant to High

    Type

    Data Breach

    Summary

    The BSNL data breach confirmed by India on July 24, 2024, involved the compromise of around 278GB of sensitive data including IMSI numbers, SIM card details, HLR specifics, DP Card Data, and snapshots of BSNL’s SOLARIS servers, all leaked by the threat actor "kiberphant0m" on BreachForums. Notably, CERT-In's investigation discovered that the breach involved one FTP server containing data similar to the leaked samples but did not affect the Home Location Register, averting any service outages.

    Severity

    The BSNL data breach, which exposed millions of user records, including sensitive SIM card details and call logs, represents a substantial cybersecurity incident. The leaked data includes international Mobile Subscriber Identity (IMSI) numbers, Home Location Register (HLR) specifications, and snapshots of BSNL’s servers, raising concerns about potential SIM cloning and interception of communications. Despite not leading to service outages, the compromised data poses significant risks for affected users.

    Considering the impact, the sophistication of the attack, the number of people affected, a...
    Show more

    Impact

    The BSNL data breach had significant repercussions, exposing millions of user records, including sensitive SIM card details, IMSI numbers, and call logs. This type of data can be exploited for SIM cloning, potentially leading to unauthorized access and interception of user communications.

    Although BSNL’s services were not taken offline, one of their servers was confirmed to have been compromised according to the data samples shared by CERT-In. There was no indication of stolen internal company data or proprietary intellectual property; however, the exposure of call logs for May 2024 and 2020...
    Show more