HomeSecurityGaana.com Hacked - 10 M. Users' Data Leaked

Gaana.com Hacked – 10 M. Users' Data Leaked

Gaana.com — one of India's most popular music streaming services with more than 10 million registered users and 7.5 million monthly visitors — was hacked, according to information published a few days ago, exposing the site's database of user details.

Gaana.com Hacked - 10 M. Users' Data Leaked

A Pakistani hacker, who claimed responsibility for the hack, claims that the data of over 10 million Gaana users including usernames, email addresses, MD5-encrypted passwords, dates of birth, and other personal information have been stolen and formed a very interesting database.

A few days ago, the Gaana website was down for maintenance, without any official announcement. There was simply the message: “Site is down due to server maintenance. We will be back shortly. Kindly bear with us till then.”

Details of 10 million users are available in a database:

The hacker, who goes by the nickname Mak Man Mak, posted a link to a searchable database of Gaana user details on his Facebook page, with images from the service's admin panel.

Gaana.com Hacked - 10 M. Users' Data Leaked

By exploiting a SQL injection vulnerability in the Gaana website, Mak Man managed to gain access to the details of 10 million of its users. The hacker also posted a screenshot of the SQL exploit he used to gain access to the data on his Facebook.

Mak Man claimed that he had discovered the vulnerability of the website in the past, making every detail of the flaw public on Gaana.com. However, the company did not respond to his report, he was ignored by security officials, which ultimately led him to breach the service's innocent users, exposing their personal information.

The defect had been reported to the company, but was ignored:

It is truly strange that Gaana, which is owned by one of India's largest internet companies, Times Internet Limited, is vulnerable to such attacks. And even stranger is that it ignored the vulnerabilities that were disclosed to it, thereby putting millions of its users at risk.

Most data breaches occur due to such behavior on the part of businesses, when hackers and bug hunters responsibly report the flaws they discover, but the companies themselves ignore the issues, thus encouraging hackers to publish their customers' personal information.

1

Times Internet CEO Satyan Gajwani responded to the hacker's Facebook post later, apologizing for the company's failure to address the security issues identified by Mak Man.

“I don’t think your intention is to expose the personal data of Gaana users, but to highlight a vulnerability,” Mr. Gajwani added. “You can be sure that you have succeeded. Can I request that you revoke access to the data, and permanently delete it?”

Gajwani tweeted that the company is taking the issue seriously and is taking steps to fix it. He also said that no financial or other sensitive user information has been leaked. He also encouraged all customers to change their passwords as soon as possible.

However, simply changing the password on your Gaana account will not solve the problem, as they will also be automatically updated in the leaked database.

It would be a good idea to deactivate your account until the issue is resolved. Additionally, change your email, Facebook, and Twitter passwords if you use the same ones as you do on Gaana.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS