Government Confirms BSNL Data Breach, Forms Telecom Security Panel

The Union government has confirmed a data breach in Bharat Sanchar Nigam Limited (BSNL) systems, reported on May 20, 2024. The Indian Computer Emergency Response Team (CERT-In) identified a possible intrusion and data breach at BSNL, according to Minister of State for Communications Chandra Sekhar Pemmasani.

In a written response to a query by Congress MP Amar Singh in the Lok Sabha, Dr. Pemmasani stated that the breach did not lead to any service outages. However, one BSNL server contained data similar to the sample data provided by CERT-In.

The breach, reported by the London-based Athenian Tech in June, involved a significant amount of sensitive information. This included International Mobile Subscriber Identity (IMSI) numbers, SIM card details, and Home Location Register (HLR) information. The compromised data was critical enough to potentially allow hackers to clone SIM cards and infiltrate BSNL’s networks.

To address the security concerns, an inter-ministerial committee has been established to audit telecom networks and recommend measures to prevent future data breaches. Dr. Pemmasani emphasized the committee’s role in conducting a thorough audit and implementing remedial measures to enhance the security of telecom networks.

The government’s swift action underscores the importance of safeguarding sensitive data and maintaining the integrity of the country’s telecom infrastructure. The newly formed committee will play a crucial role in fortifying security protocols and ensuring the resilience of telecom networks against cyber threats.