hidden image

Data at risk: Citizens to suffer

Jaswant Kaur Jaswant Kaur
12 Apr 2021

This has not happened for the first time. Yet, it escaped the attention of many. The data leak story that hit the headlines last week has raised an alarm over the kind of risk we all face in this digital world.
 
A report from cyber security experts claimed that a database of around 3.5 million customers linked with fintech service provider MobiKwik has been put on sale on the worldwide dark web. 

An anonymous hacker has offered to sell 8.5 terabyte database, containing email id, phone number, password, physical address details, soft copies of identification documents etc. for US$ 75,000, payable in cryptocurrency.
 
For an average Indian citizen, one terabyte data actually means around 500 two-hour long movies. It is difficult to even imagine how much data 8.5 TB would contain!
 
MobiKwik is one of the first companies, to have launched the online payment solutions and wallet. Like PayTM, it had acquired millions of customers quite quickly. Instead of resolving this sensitive issue, the expert who initially brought up this issue was targeted in a vilification campaign. Not only this, attempts were made to even close his social media accounts.
 
The company conveniently denied the incident and claimed that it has not observed any data breach in the month of February 2021 as claimed by the hacker. However, when the Reserve Bank of India took note of the incident, it had to agree to conduct a forensic audit. 

The company also mentioned that the users could have uploaded their information on several other platforms, it would be difficult to say that the database was leaked from its website.
 
The fact is that the digital world has its own permutations and combinations. However stringent one’s privacy policy or measures may be, it takes a few minutes for cyber criminals to breach the security. It only means that theft has now acquired new dimensions. In view of the complex environment, it becomes really difficult for the cybercrime experts to catch such tech thieves.
 
In fact, the disclosure norms of MobiKwik itself shows how fragile this tech world is. The company in its privacy policy says that “although we make good-faith efforts to store information in a secure operating environment that is not open to the general public, you should understand that there is no such thing as complete security and we do not guarantee that there will be no unintended disclosures of your Information. 

“If we become aware that your Information has been disclosed in a manner not in accordance with this Privacy Policy, we will use reasonable efforts to notify you of the nature and extent of the disclosure (to the extent we know that information) as soon as reasonably possible and as permitted by law.”
 
On the one hand the company accepts the vulnerability of data but on the other, it did not even accept any data breach, forget informing the customers, whose data has been put on sale. And so is the case with many other companies. However, we as consumers are more vulnerable in the current scenario than ever.
 
With the pandemic disrupting businesses, companies were quick to adopt work from home as the new norm. Clearly, the database that the employees initially accessed from a closed environment in an office set-up, was opened for remote access. It has certainly been a boon for cyber criminals, who look for such opportunities. Small wonder that the year 2020 saw one of the largest number of data breaches globally. The threat has been increasing by leaps and bounds, considering that the pandemic will stay for another few years.
 
Kaspersky, an antivirus company, has revealed that the total number of brute force attacks against remote desktop protocol (RDP) increased from 93 million in February 2020 to 277.4 million in March 2020 when the world went into strict lockdown. One can imagine the kind of risks we all face. 

In India alone such attacks shot up from 1.3 million to 3.3 million in the same period. Since April 2020, monthly global attacks never went below 300 million, touching a new high of 400 million in the month of November. India recorded the highest number of attacks in the month of July 2020 when data breaches crossed 4.5 million!
 
And there is no end to it. By the end of February 2021, India alone saw 9.04 million attacks. India may or may not be the favourite destination for foreign investors but it has certainly become one of the favourites for cyber criminals.
 
Be it Big Basket, JusPay, PayTM, Aadhaar or even the largest bank State Bank of India, all of them faced these attacks. In fact, even the much-publicised payment solution, Bhim app, could not evade such an attack. 

Of late, personal information of around 5,00,000 police personnel was also put up for sale! Not only this, in the month of February, database of the army personnel posted in Jammu and Kashmir was also posted in the worldwide dark web. Imagine the ones who have been entrusted with the responsibility of protecting the common man — their database, too, is equally vulnerable.
 
Unlike other organisations, MobiKwik has been continuously denying claims of any data breach. And why should it not? The company is planning to announce an initial public offering (IPO) to raise US$ 200 to US$ 250 million in September this year. Such a news will certainly be a setback for its growth plans. However, going into denial mode and not taking necessary action, will do it more damage.
 
Be that as it may, the question that comes to mind is why is it easy for the hackers to attack Indian databases? What has made it more vulnerable, compared to other countries of the world. The answer lies in the legal framework.
 
Laws in India have been ambiguous over data privacy for a long time. However, in the year 2017, the Supreme Court of India held that the right to privacy was a part of the right to life and personal liberty as enshrined in the Constitution. 

The ruling came in the light of questions raised over privacy issues, safety of biometric data and iris scans collected under the ambitious Aadhar scheme. The debate and the European Union’s initiative of implementing the general data protection regulation (GDPR) certainly forced the Indian government to think over legal provisions protecting data and privacy.
 
As a result, a personal data protection Bill was drafted. However, it was highly criticised on certain fronts and could not become a law. Many dubbed it as a tool that can be used for surveillance and invading the privacy of citizens in the name of national security. 

The government has so far not been able to win the confidence of either the legislators or the common man. The focus should have been on holding constructive discussions to modify the Bill. Meanwhile, hackers are certainly having a free run.
 
Small wonder that, the famous messaging app, WhatsApp brought in a major change in its privacy policy, forcing many to migrate to apps like Signal and Telegram. A recent meme showed the Facebook CEO Mark Zuckerberg messaging on an app other than WhatsApp. Experts claim that WhatsApp could not have dared to bring such a big change in its privacy policy if we had a strong legal framework in place.
 
While digital India has certainly opened new avenues for start-ups, it has also given way to new and complex forms of cyber-crime. At stake is the privacy and security of the common man, who in any case, has no means to protect himself. 

He is certainly at the mercy of the powers that be and the tech firms he relies on for simple payment solutions. They say trust begets trust. At no point should it be counter-productive.

(The writer, a company secretary, can be reached at jassi.rai@gmail.com)

Recent Posts

The world today rewards arrogance, violence, and deceit, rewriting the Beatitudes for the powerful. Yet history shows that such triumphs are fleeting. True strength lies in respect, moderation, and co
apicture Thomas Menamparampil
06 Oct 2025
Twenty-two years from now, in 2047, when India marks a hundred years of Independence, let future generations remember that Shri Bhagwant Mann Ji stood for freedom, not fear; for reason, not repression
apicture A. J. Philip
06 Oct 2025
Hatred and revenge, amplified by politics, technology, and mass media, are eroding democracies and poisoning societies from America to India. Unless citizens demand accountability and reject divisive
apicture Jacob Peenikaparambil
06 Oct 2025
A farmer in Nashik helplessly watches his onion harvest rot in the open after the rains collapse the roof of the local storage. A group of farmers in Bihar throws tonnes of tomatoes on the road as the
apicture Jaswant Kaur
06 Oct 2025
The Sangh Parivar's march to a Hindu Rashtra is neither accidental nor benign—it thrives on strife, thrives on mobs, and erodes the soul. To dismiss this as alarmism is to ignore a storm gathering on
apicture Mathew John
06 Oct 2025
Arunachal's youth turned faith into testimony, not coercion. By living dignity and service, they quietly dismantled a law born of cultural anxiety. Their stories show that evangelisation was never abo
apicture CM Paul
06 Oct 2025
By delaying the census and imposing a flawed Special Intensive Review in Bihar, the BJP is weaponising citizenship itself. Ordinary citizens now struggle to prove their very existence, while constitut
apicture Prakash Louis
06 Oct 2025
As Bengal and other parts of India, where Durga Puja is celebrated, prepare for the immersion of the goddess, the reflection continues to circulate not merely as a viral post, but more as a theologica
apicture IP Sarto, Asansol
06 Oct 2025
Please understand, the louder the noise, the less the truth. The calmer the tone, the greater the honesty. But then comes the real question: where do you tune in? Do you continue to feed on the off
apicture Robert Clements
06 Oct 2025
India can learn much from Sri Lanka—discipline on the roads, cleanliness in public spaces, honesty in trade, and humility in politics. These everyday practices demonstrate how small acts of integrity
apicture A. J. Philip
29 Sep 2025