{"id":54109,"date":"2021-01-24T09:01:29","date_gmt":"2021-01-24T09:01:29","guid":{"rendered":"https:\/\/www.cryptocabaret.com\/?p=54109"},"modified":"2021-01-24T09:01:29","modified_gmt":"2021-01-24T09:01:29","slug":"indian-crypto-exchange-buyucoin-hacked-sensitive-data-of-325k-users-reportedly-leaked","status":"publish","type":"post","link":"https:\/\/www.cryptocabaret.com\/?p=54109","title":{"rendered":"Indian Crypto Exchange Buyucoin Hacked, Sensitive Data of 325K Users Reportedly Leaked"},"content":{"rendered":"<p><img decoding=\"async\" width=\"696\" height=\"392\" src=\"https:\/\/www.cryptocabaret.com\/wp-content\/uploads\/2021\/01\/buyucoin-hacked-768x432.jpg\" class=\"attachment-medium_large size-medium_large wp-post-image\" alt=\"Indian Crypto Exchange Buyucoin Hacked, Sensitive Data of 325K Users Reportedly Leaked\" loading=\"lazy\" srcset=\"https:\/\/www.cryptocabaret.com\/wp-content\/uploads\/2021\/01\/buyucoin-hacked-768x432.jpg 768w, https:\/\/news.bitcoin.com\/wp-content\/uploads\/2019\/09\/buyucoin-hacked-300x169.jpg 300w, https:\/\/news.bitcoin.com\/wp-content\/uploads\/2019\/09\/buyucoin-hacked-1024x576.jpg 1024w, https:\/\/news.bitcoin.com\/wp-content\/uploads\/2019\/09\/buyucoin-hacked-696x392.jpg 696w, https:\/\/news.bitcoin.com\/wp-content\/uploads\/2019\/09\/buyucoin-hacked-1068x601.jpg 1068w, https:\/\/news.bitcoin.com\/wp-content\/uploads\/2019\/09\/buyucoin-hacked-747x420.jpg 747w, https:\/\/news.bitcoin.com\/wp-content\/uploads\/2019\/09\/buyucoin-hacked-190x107.jpg 190w, https:\/\/news.bitcoin.com\/wp-content\/uploads\/2019\/09\/buyucoin-hacked-380x214.jpg 380w, https:\/\/news.bitcoin.com\/wp-content\/uploads\/2019\/09\/buyucoin-hacked-760x428.jpg 760w, https:\/\/news.bitcoin.com\/wp-content\/uploads\/2019\/09\/buyucoin-hacked.jpg 1280w\" sizes=\"auto, (max-width: 696px) 100vw, 696px\"><\/p>\n<p><strong>Indian cryptocurrency exchange Buyucoin has reportedly been hacked and sensitive data of about 325,000 users has reportedly been leaked onto the dark web. According to reports, the leaked data includes personal information, encrypted passwords, user wallet details, order details, bank details, PAN numbers, passport numbers, and deposit histories.<\/strong><\/p>\n<h2>Indian Cryptocurrency Exchange Hacked<\/h2>\n<p>Buyucoin, a Delhi NCR-based cryptocurrency exchange, has reportedly been hacked. The exchange has more than 350K registered users and has facilitated over $500 million in cryptocurrency trades, according to its website. Several local news outlets reported that sensitive data of about 325K customers has been dumped onto the dark web. IANS publication detailed on Friday:<\/p>\n<blockquote>\n<p>The data leaked include names, e-mails, mobile numbers, encrypted passwords, user wallet details, order details, bank details, KYC details (PAN number, passport numbers) and deposit history.<\/p>\n<\/blockquote>\n<p>Independent cybersecurity researcher Rajshekhar Rajaharia explained to the publication that the 6GB file on MongoDB database contains three backup files with Buyucoin data. The researcher also found his own information that he used to create an account on the platform last year among the leaked data. \u201cThis is a serious hack as key financial, banking and KYC details have been leaked on the dark web,\u201d Rajaharia was quoted as saying.<\/p>\n<p>On Twitter, a number of users said that their information was leaked. Rajaharia <a href=\"https:\/\/twitter.com\/rajaharia\/status\/1352227184136491008\" target=\"_blank\" rel=\"noopener noreferrer\">tweeted<\/a>: \u201cTrading in cryptocurrency? 3.5 Lakh Users data including me leaked from Buyucoin. The leaked data contains name, email, mobile, bank account numbers, PAN number, wallets details etc. Again didn\u2019t informed to affected users by company.\u201d<\/p>\n<p><img decoding=\"async\" loading=\"lazy\" class=\"aligncenter wp-image-437906\" src=\"https:\/\/www.cryptocabaret.com\/wp-content\/uploads\/2021\/01\/buyucoin-twitter-726x1024.jpg\" alt=\"\" width=\"400\" height=\"564\" srcset=\"https:\/\/www.cryptocabaret.com\/wp-content\/uploads\/2021\/01\/buyucoin-twitter-726x1024.jpg 726w, https:\/\/news.bitcoin.com\/wp-content\/uploads\/2019\/09\/buyucoin-twitter-213x300.jpg 213w, https:\/\/news.bitcoin.com\/wp-content\/uploads\/2019\/09\/buyucoin-twitter-768x1083.jpg 768w, https:\/\/news.bitcoin.com\/wp-content\/uploads\/2019\/09\/buyucoin-twitter-696x982.jpg 696w, https:\/\/news.bitcoin.com\/wp-content\/uploads\/2019\/09\/buyucoin-twitter-1068x1506.jpg 1068w, https:\/\/news.bitcoin.com\/wp-content\/uploads\/2019\/09\/buyucoin-twitter-298x420.jpg 298w, https:\/\/news.bitcoin.com\/wp-content\/uploads\/2019\/09\/buyucoin-twitter.jpg 1079w\" sizes=\"auto, (max-width: 400px) 100vw, 400px\"><\/p>\n<p>Buyucoin is the latest victim of the infamous hacker group Shinyhunters, which has been leaking databases for free on well-known English-speaking forums, according to the Economic Times. The group also leaked data of e-grocer Big Basket, educational technology platform Unacademy and payment aggregator Juspay.<\/p>\n<p>Israel-based darknet threat intelligence provider KELA confirmed the leak to the publication. The firm\u2019s threat intelligence analyst Victoria Kivilevich explained that \u201cThese records are now circulating on the dark web and available for use by other cyber criminals.\u201d She added that they can use the data for anything from \u201cphishing scams to gaining admin privileges and access into corporate networks if corporate credentials have been leaked.\u201d<\/p>\n<h2>Buyucoin Is Investigating the Breach<\/h2>\n<p>Since reports of the security breach emerged, Buyucoin has released two official statements on the matter. The first was written by its CEO, Shivam Thakral. He wrote: \u201cIn the mid of 2020, while conducting a routine testing exercise with dummy data, we faced a \u2018low impact security incident\u2019 in which non-sensitive, dummy data of only 200 entries were impacted. We would like to clarify that not even a single customer was affected during the incident.\u201d<\/p>\n<p>Rajaharia responded to the exchange\u2019s official statement in a tweet: \u201cSuch an irresponsible statement by Buyucoin. I am your registered and KYC verified user. You leaked my own data too. Please change your statement asap. What if someone used my account in any illegal activity. Please inform your users right now.\u201d<\/p>\n<p><!-- growjs zone placement 31 --> <ins> <ins class=\"growjs-placement\"><\/ins> <\/ins> <!-- end of growjs zone placement --> <\/p>\n<p>The Buyucoin CEO\u2019s message was subsequently replaced with a different one by the exchange. \u201cRegarding the media report,\u201d Buyucoin wrote:<\/p>\n<blockquote>\n<p>We are thoroughly investigating each and every aspect of the report about malicious and unlawful cybercrime activities by foreign entities in mid-2020.<\/p>\n<\/blockquote>\n<p>There have been no further updates from the exchange at press time.<\/p>\n<p><em><strong>What do you think about this Buyucoin hack? Let us know in the comments section below.<\/strong><\/em><\/p>\n<p class=\"wpematico_credit\"><small>Powered by <a href=\"http:\/\/www.wpematico.com\" target=\"_blank\" rel=\"noopener noreferrer\">WPeMatico<\/a><\/small><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Indian cryptocurrency exchange Buyucoin has reportedly been hacked and sensitive data of about 325,000 users has reportedly been leaked onto the dark web. According to reports, the leaked data includes personal information, encrypted passwords, user wallet details, order details, bank details, PAN numbers, passport numbers, and deposit histories. Indian Cryptocurrency Exchange Hacked Buyucoin, a Delhi [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":54110,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[309],"tags":[],"class_list":["post-54109","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cryptocurrency"],"_links":{"self":[{"href":"https:\/\/www.cryptocabaret.com\/index.php?rest_route=\/wp\/v2\/posts\/54109","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.cryptocabaret.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.cryptocabaret.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.cryptocabaret.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.cryptocabaret.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=54109"}],"version-history":[{"count":0,"href":"https:\/\/www.cryptocabaret.com\/index.php?rest_route=\/wp\/v2\/posts\/54109\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.cryptocabaret.com\/index.php?rest_route=\/wp\/v2\/media\/54110"}],"wp:attachment":[{"href":"https:\/\/www.cryptocabaret.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=54109"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.cryptocabaret.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=54109"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.cryptocabaret.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=54109"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}