Responsive Image with Divider
Responsive Image

Govt welfare data allegedly on the Dark Web: Cyberattack claims across many states

An investigative report based on the evidence and claims published in a newspaper investigation makes stunning claims of massive data leak due to lack of cyber security measures
Alt="CBRN Threats"
Govt welfare data allegedly on the Dark Web: Cyberattack claims across many statesPSU Watch
Published on

New Delhi: A recent investigation report published in a national daily has raised serious questions over the security of beneficiary data held by government welfare schemes across the states like Chhattisgarh, Bihar, Rajasthan and Madhya Pradesh. According to the report, a team spent nearly 100 hours monitoring the dark web and cybercrime marketplaces and found what appeared to be government-related beneficiary databases, login credentials and other sensitive information being offered for sale.

The investigation claims that some of the data was being marketed through Russian-language or Russia-linked cybercrime marketplaces, with certain datasets reportedly being offered for as little as $10.

Follow The PSUWatch Channel on WhatsApp

If independently verified, the allegations would represent a significant failure in the protection of citizens’ personal information.

But there is an important distinction that must be made at the outset:

”Finding data on the dark web does not, by itself, prove that the data was stolen directly from the government server named in the listing.”

Establishing the source of a breach requires forensic evidence—server logs, database records, malware traces, authentication logs, timestamps and evidence connecting the stolen information to a particular system.

The allegations are therefore best treated as serious breach claims requiring immediate forensic verification, rather than as conclusively established hacks.

The four cases at the centre of the investigation

Chhattisgarh: Mahatari Vandan Yojana beneficiary data allegedly offered for sale

The investigation identifies the Mahatari Vandan Yojana in Chhattisgarh as one of the systems whose data was allegedly compromised.

According to the report, beneficiary information associated with the scheme’s website was found being offered in cybercrime marketplaces.

The newspaper says that an initial sample of 372 beneficiaries’ records was found in different dark-web groups and was reportedly being offered for around $10.

The significance goes beyond the monetary value of the data.

A welfare-scheme database can potentially contain combinations of:

  • Names

  • Mobile numbers

  • Addresses

  • Beneficiary information

  • Banking-related details

  • Identity information

  • Scheme/payment information

Such combinations can be extremely valuable to fraudsters because they allow highly targeted impersonation and phishing attacks.

However, the screenshots published in the investigation alone cannot establish whether the records were genuine, current, or stolen directly from the government system.

That distinction must be resolved through forensic examination.

Alt="CBRN Threats"
Suspicious foreign remittances of 394 entities under IT department scanner

Bihar: Alleged theft of more than eight lakh beneficiary records

The Bihar case raises an even more serious set of questions.

The report refers to systems associated with SSPMIS Bihar and the 7-Nischay portal and claims that data relating to more than eight lakh beneficiaries had been stolen.

According to the newspaper investigation:

  • More than 800,000 beneficiary records were allegedly obtained.

  • A seller reportedly demanded $2,000 for one million records.

  • The investigation also claims that important departmental accounts had been targeted and that their login credentials were allegedly available in cybercrime markets.

The last allegation is potentially more serious than the sale of beneficiary information itself.

If a privileged government account has actually been compromised, the threat can extend beyond data theft. An attacker with sufficient privileges may potentially be able to:

  • Access additional databases;

  • Download large quantities of information;

  • Alter records;

  • Create or manipulate accounts;

  • Introduce fraudulent beneficiaries;

  • Move laterally into other systems.

The newspaper’s investigation therefore warrants a review not merely of the public-facing portal but of administrator accounts, authentication systems, endpoint devices and privileged-access logs.

The common thread: stolen credentials may be more dangerous than stolen databases

One of the most significant patterns emerging from the investigation is that the alleged incidents are not limited to the sale of beneficiary information.

The report points towards a broader ecosystem involving:

Malware → stolen credentials → account compromise → privileged access → data theft → resale

The newspaper specifically refers to information-stealing malware such as RedLine and Lumma, among other malicious tools.

This is important because modern government cyberattacks do not necessarily require an attacker to “break into” a heavily protected government server.

An attacker may instead compromise:

1. An employee’s computer;

2. A contractor’s computer;

3. A browser containing saved credentials;

4. An administrator’s account;

5. An exposed API;

6. A cloud or application token.

Once valid credentials are stolen, the attacker can potentially appear to the system as a legitimate user.

That makes identity security and endpoint security just as important as perimeter security.

The crucial investigative question: Where did the data actually come from?

The biggest weakness in any dark-web breach investigation is attribution.

A database appearing for sale online can originate from several sources:

1. Direct server intrusion

The attacker penetrated the government’s infrastructure and extracted the database.

2. Third-party vendor compromise

A contractor or technology provider holding a copy of the data was compromised.

3. Exposed API or database

A misconfigured application may have made data accessible without adequate authentication.

4. Compromised employee credentials

An attacker acquired legitimate credentials through phishing or malware.

5. Malware infection

An information-stealing Trojan extracted passwords, browser data or authentication tokens.

6. An older breach

Data stolen years earlier may be repackaged and resold as a new breach.

7. Fabricated or recycled data

Cybercriminals sometimes advertise samples that are incomplete, outdated, publicly available or entirely fabricated.

For that reason, the assertion:

“The data is on the dark web, therefore the government website was hacked”

would not meet the standard of forensic proof.

The central question is data provenance—how the information moved from the original system into the hands of the alleged seller.

Follow PSU Watch on Linked

Alt="CBRN Threats"
Suspicious foreign remittances of 394 entities under IT department scanner

The human cost could be much greater than the price of the stolen data

The apparent prices mentioned in the investigation—such as $10 for a small dataset—can create the misleading impression that the information itself is of low value.

That is not necessarily the case.

A criminal does not necessarily need to make money by reselling the same database.

Suppose a fraudster obtains a person’s:

  • Name;

  • Mobile number;

  • Government-scheme details;

  • Address;

  • Identity information;

  • Banking-related information.

The criminal can then make a highly credible telephone call:

“Your government benefit payment is pending. Please complete your KYC.”

Or:

“Your subsidy has been stopped. We need to verify your Aadhaar/OTP.”

Because the criminal already knows that the person is a beneficiary, the victim is more likely to believe the caller.

This is why a data breach can become a financial-fraud problem, even when the original stolen database is sold for a relatively small amount.

(PSU Watch is India's Business News centre that places the spotlight on PSUs, Bureaucracy, Defence and Public Policy. 👉 Click to join our channel now: PSUWatch WhatsApp Channel. Prefer LinkedIn? Follow PSU Watch on LinkedIN. Click to stay connected on Twitter here and stay updated)

logo
PSU Watch
psuwatch.com