A few days ago, online grocery shopping platform Bigbasket was hacked. And as discovered by cybersecurity firm Cyble , a hacking group called “ Shinyhunters ” is likely behind the data breach .

The company discovered a conversation between another cybercriminal and “Shinyhunters” on RaidForums on November 10. Shinyhunters is a group known for its active online shopping, hacking, and previously selling a database containing a total of 73.2 million users from 11 different companies. The group is said to have been operating since 2015 under a variety of aliases including Shiny Hunters ,Gnostic Players , and others.
On November 8, BigBasket had filed a police complaint with the Cyber Crime Cell of Bangalore and is verifying the allegations of cyber experts.
Cyble said that a malicious actor had sold data, allegedly belonging to BigBasket, for around INR 30 million. The company claimed that the breach took place on October 30, 2020 and has already informed the Bigbasket management about it.
"A few days ago, we learned of a potential data breach at BigBasket and we are assessing the extent of the breach and the authenticity of the claim in consultation with experts and finding immediate ways to mitigate it. We have also filed a complaint with the Cyber Crime Cell, Bangalore and intend to pursue it to bring the culprits to justice," BigBasket said.
The company added that it does not store financial data, including credit card numbers, on its servers and is confident that all financial data related to its users is secure. “The only customer data we hold is email IDs, phone numbers, order details and addresses, so these are the details that could potentially have been compromised. We have a robust information security framework that uses best-in-class resources and technologies to manage our information. We will continue to proactively work with the best information security experts to further strengthen it,” Bigbasket said when it discovered the breach.
