Online grocery shopping platform, BigBasket, is the latest case of cyberattack in India.

As reported by cyber security firm Cyble, the personal data of approximately 20 million BigBasket users has been released for sale on the dark web.
The data, which is being sold for $40,000, includes, among other information, full names, email IDs, hashed passwords, PINs, contact numbers, addresses, dates of birth, location, and login IP addresses.
The Bangalore-based company has filed a complaint with the city's cybersecurity authority and is trying to assess the extent of the breach in collaboration with cybersecurity experts.
"The privacy and confidentiality of our customers is our priority and we do not store financial data, including credit card numbers, and we are confident that this financial data is secure," the Alibaba -backed company said .
"The only customer data we hold is email IDs, phone numbers, order details and addresses, so these are the details that could potentially have been compromised. We have a robust information security framework that uses best-in-class resources and technologies to manage our information," he added.

According to Cyble, the alleged breach occurred on October 14th and BigBasket management was notified of it on November 1st.
Of course, BigBasket is not the only company to have been breached. Many online shopping platforms have been attacked by malicious actors and their user data has been exposed online and in illegal forums around the world.
Internet security experts say that while online commerce has made our lives easier, it also brings new risks to the security of our data, as it becomes an increasingly popular target for cybercriminals . They recommend that users be careful about the details they give out, not to use the same passwords and if they notice suspicious movements in their accounts, to contact their bank immediately.
