BSNL Hit by Another Data Breach in Six Months

Bharat Sanchar Nigam Ltd (BSNL) has experienced a significant data breach, with a threat actor claiming to have accessed sensitive information, including international mobile subscriber identity (IMSI) numbers, SIM card details, home location register data, and critical security keys, according to a report by digital risk management firm Athentian Tech.

The breach, attributed to a threat actor named “kiberphant0m,” allegedly involved over 278 GB of data from BSNL’s telecom operations, including server snapshots. This compromised data could be exploited for SIM cloning and more severe criminal activities, such as extortion, Athentian Tech CEO Kanishk Gaur told ET.

This incident marks the second data breach for the state-owned telecom operator in six months. The Economic Times had reported a previous breach in December last year.

The threat actor has publicly priced the stolen data at $5,000, with Gaur describing the breached data as “complex and critical,” surpassing typical user information and targeting the core of BSNL’s operational systems. Queries sent to BSNL remained unanswered as of press time on Tuesday.

Gaur emphasized that the detailed operational data compromised in the breach could be used to launch sophisticated cyber-attacks, posing significant risks not only to BSNL but also to interconnected systems and networks, potentially affecting national security. With access to SIM card information and authentication keys, attackers could bypass security measures on financial accounts, leading to financial losses and identity theft for users.

“BSNL should initiate an urgent investigation to assess and contain the breach,” Gaur advised. “Immediate steps include securing network endpoints and auditing access logs.” He also recommended that BSNL implement enhanced security measures, including frequent security audits and the adoption of advanced threat detection technologies.

In last year’s breach, a threat actor using the alias “Perell” had disclosed a “sample dataset” on a dark web forum, including sensitive details of fiber and landline users of BSNL. This dataset contained about 32,000 lines of data, and the threat actor claimed that the total number of lines across all databases amounted to over 2.9 million. The compromised data included email addresses, billing details, contact numbers, and other sensitive information, as well as mobile outage records, network details, completed orders, and customer information.

This time, the threat actor has confirmed that the data being sold is distinct and unrelated to previously sold datasets, which focused on user information. The current data is described as more complex and critical, relating directly to telecom operations.