Menu
Browse
Date:

Dec 2016

Location:

India

Summary

The Indian Institute of Technology Kharagpur experienced a data breach when hacker Cryptolulz666 exploited an SQL injection vulnerability in its website, compromising over 12,000 user records containing emails, passwords, phone numbers, and security questions. The attacker leaked a limited subset of the data on Pastebin as proof while withholding the majority to avoid potential legal repercussions for the institution. Cryptolulz666 claimed the intrusion aimed to highlight security deficiencies and prompt improved protections, emphasizing that unaddressed flaws risked exploitation by malicious actors. This incident followed the hacker's prior breaches targeting other entities, including a Russian embassy database and distributed denial-of-service attacks against government websites.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actor Type Location
1 actor Available to members Available to members

Description

On December 19, 2016, the Indian Institute of Technology Kharagpur (IIT Kharagpur) experienced a data breach perpetrated by the hacker known as Cryptolulz666. The intrusion occurred approximately 24 hours after a separate attack on IIT Bombay, indicating a pattern of targeting Indian academic institutions. Cryptolulz666 exploited an error-based SQL injection vulnerability in the IIT Kharagpur website (iitkgp.ac.in) to gain unauthorized access to the institution's database. The compromised database contained records for 12,555 users, including email addresses, passwords, phone numbers, and security question answers. As proof of the breach, the hacker publicly leaked a subset of the stolen records on Pastebin, though they intentionally limited the disclosure to less than a quarter of the total dataset to avoid potential legal consequences for the institution.

Cyber Incident Image

Cryptolulz666 explicitly stated their motivation was to highlight cybersecurity deficiencies in institutional websites, emphasizing that organizations must implement comprehensive protection measures. The hacker warned that malicious actors could exploit such vulnerabilities for harmful purposes if left unaddressed. This incident followed Cryptolulz666's prior breach of the Russian Embassy in Armenia's website and coincided with distributed denial-of-service (DDoS) attacks against Russian and Italian government websites attributed to the same actor. No information regarding IIT Kharagpur's detection methods, containment procedures, or post-incident response was disclosed in available sources. The breach exposed sensitive personal information of thousands of users, creating potential risks of credential reuse and targeted phishing campaigns against affected individuals.

Sources
Sources available to members
1 source