IRCTC plugs critical data breach on insurance portal 

S. Vijay Kumar S. Vijay Kumar | 08-05 16:20

The Indian Railway Catering and Tourism Corporation (IRCTC) has addressed a critical vulnerability on its insurance portal that previously allowed unauthorised access to passengers’ travel details and enabled changes to nominee information in the insurance policy.

Cybersecurity researcher Nilabh Rajpoot of Noida discovered the bug after booking train tickets on the IRCTC website and opting for travel insurance. He received a link via SMS that, upon entering the PNR and registered mobile number, opened the travel insurance policy provided by United India Insurance Co Ltd. The link included an option to update nominee details.

Mr. Rajpoot’s curiosity and hacker instincts led him to investigate potential data leaks on the portal. By entering random PNRs and fictitious mobile phone numbers, he found that the portal revealed passengers’ travel details, such as journey date, train number, berth/seat, email, mobile phone, and insurance policy information. Shockingly, the portal allowed modification of nominee details without requiring an OTP or security question.

Random PNRs

“I entered hundreds of random PNRs and mobile phone numbers and accessed passengers’ travel/insurance details. Although the link issued an alert that the mobile number did not exist, it still provided the passenger data. I immediately reported the issue on July 23, 2024, to the Computer Emergency Response Team – India (CERT-In), which communicated the vulnerability to the relevant organisation,” Mr. Rajpoot told The Hindu on Sunday.

In a reply on July 30, 2024, CERT-In said the concerned organisation had confirmed that the vulnerability had been fixed and requested him to verify at his end.

The vulnerability on the IRCTC insurance portal was significant as it exposed sensitive passenger information, including journey and contact details. Although the issue was found on the insurance portal managed by a third party, the data security and privacy concerns affected IRCTC as the custodian.

Mr. Rajpoot focuses on identifying and mitigating security risks through routine assessments of various online portals. “In this case, unauthorised individuals could access and modify policyholders’ details, including nominee information. We must protect sensitive information from fraudulent access and manipulation,” he said.

Disclaimer: The copyright of this article belongs to the original author. Reposting this article is solely for the purpose of information dissemination and does not constitute any investment advice. If there is any infringement, please contact us immediately. We will make corrections or deletions as necessary. Thank you.


ALSO READ

Ola Electric responds to ARAI notice, says prices of S1 X 2 kWh scooter unchanged

Ola Electric provided an invoice dated October 6, showing a INR 5,000 discount given to customers, a...

Hyundai Motor IPO’s off to a slow start

Around 35% of the total shares in the offering are reserved for retail investors, while QIBs and NII...

Under fire, Ola Electric taps EY India to get back on track

Close to a dozen executives from EY came on-board at Ola Electric a few weeks ago on deputation for ...

Tata Motors secures 5-star BNCAP safety ratings for Nexon, Curvv, and EV models in latest crash tests

Tata Curvv.EV BNCAP testTata Motors did it again! Tata Motors has once again secured 5 star rating i...

India needs to step up manufacturing to meet Viksit Bharat goal: Volvo Grp India MD

Volvo Group India Managing Director and President, Kamal Bali. The manufacturing sector is a weak li...

Dollar pullback to help Indian rupee, weak risk appetite to weigh

Investors are now nearly certain that the U.S. Federal Reserve will deliver a 25-basis-point rate cu...