The personal data of 7 million credit and debit card users in India has been leaked on the Dark Web in the last month.

The leaked data reveals that the 2GB database, which is located on a public Google Drive link , includes cardholder names, phone numbers, email addresses, employer company names, annual income, account types, etc. Further, the leaked database also includes PAN numbers for 5 Lakh cardholders .
The leaked data comes from the period between 2010 and 2019.
According to cybersecurity researcher Rajshekhar Rajaharia , who alerted Inc42 to the incidents, the leaked data can be used by cybercriminals for spam messages and phishing attacks
The name of the company the cardholders work for would help criminals tailor their malicious SMS and emails so they could trick the user.
While it was not possible to verify whether the leaked data for the 7 million users is genuine or not, Inc42 and Rajaharia have verified some of these users.

It is worth noting that there is little commonality among the cardholders whose data has been leaked. The database consists of cardholders employed by companies like Axis Bank, Bharat Heavy Electricals Limited, Kellogg India Private Limited and Mckinsey and Company, among many others, with annual incomes ranging from INR 7 lakh to over INR 35 lakh.
The data leak is the latest in a series of such cyber attacks ,affecting millions of Indian users.
Experts at Inc42 reported that cyberattacks have definitely increased this year, mainly due to the pandemic and remote working.
A survey conducted by California-based security firm Barracuda Networksrevealed that about 66% of Indian companies reported at least one data breach after switching to a remote work model this year. The increase in cyber attacks comes at a time when the digitization of India's economy is projected to lead to a $435 billion opportunity by 2025.
