Fetlla
ServicesTrainingProductsEventsCertify itBlogs
ServicesTrainingProductsEventsCertify itBlogs
Articles
InsightJan 17, 2024

Hathway Data Breach: Hackers Leaks Data

Learn what happened in the Hathway data breach and how to protect your data.

Written by

Shahabas Abdul Hameed

Article guide

Contents

  1. Who is the hacker and how did they breach Hathway?
  2. What data was leaked and how much of it?
  3. How can you check if your data was exposed?
  4. What should you do if your data was exposed?
  5. What is Hathway doing about the breach?
  6. Conclusion:

Hathway, one of the largest internet service providers and cable TV operators in India, has suffered a massive data breach that exposed the personal and financial data of millions of its customers and employees. The breach occurred in December 2023, but the hacker behind it recently leaked the data online after failing to sell it.

Who is the hacker and how did they breach Hathway?

The hacker, who goes by the alias 'dawnofdevil', claims to have breached Hathway by exploiting a vulnerability in the Laravel framework application used by the company. Laravel is a popular web development framework that powers many websites and applications. However, it also has some known security issues that can allow attackers to execute arbitrary code on the server if not properly configured or updated.

The hacker says they used a tool called Laravel RCE Exploit to scan for vulnerable Laravel applications and found Hathway's website among them. They then used the exploit to gain access to the server and download the data.

What data was leaked and how much of it?

The hacker leaked two files on Breach Forums, a dark web platform where hackers buy and sell stolen data. The first file contained 12GB of personal data of more than 4 million Hathway customers, including their names, email addresses, phone numbers, home addresses, customer registration forms, copies of Adhaar cards, and KYC data. KYC stands for Know Your Customer and is a process of verifying the identity of customers by collecting documents such as identity cards, bank statements, etc.

The second file contained 214GB of personal and financial data of Hathway's employees and customers. This included salary slips, bank account details, credit card numbers, invoices, payment receipts, tax documents, etc.

The hacker claims that the data is authentic and up-to-date as of December 2023.

How can you check if your data was exposed?

The hacker also developed a dark web search engine for the victims of the data breach, allowing them to check if their data was exposed by searching for their email addresses and phone numbers. The search engine is accessible through a Tor browser, which is a software that enables anonymous browsing on the dark web.

However, using the search engine may not be safe or advisable, as it may expose you to further risks or scams. The hacker may use the search engine to collect more information about you or lure you into paying for fake services or products.

A better way to check if your data was exposed is to use a reputable service such as Have I Been Pwned, which allows you to enter your email address and see if it was involved in any data breaches. You can also sign up for notifications if your email address appears in any future breaches.

What should you do if your data was exposed?

If your data was exposed in the Hathway data breach, you should take immediate steps to protect yourself from identity theft, fraud, phishing, spam, and other cyberattacks. Here are some recommendations:

Change your passwords for all your online accounts, especially those related to your email, banking, social media, etc. Use strong and unique passwords for each account and enable two-factor authentication if possible.

Monitor your bank accounts and credit cards for any suspicious transactions or activities. Report any unauthorized charges or withdrawals to your bank or card issuer as soon as possible.

Beware of any emails, calls, or messages that claim to be from Hathway or other legitimate organizations and ask for your personal or financial information. Do not click on any links or attachments or provide any information without verifying the source and legitimacy of the communication.

Consider freezing your credit reports or placing fraud alerts on them to prevent anyone from opening new accounts or loans in your name. You can contact the three major credit bureaus in India: CIBIL, Experian , and Equifax to do so.

Review your Adhaar card details and report any discrepancies or changes to UIDAI, the authority that issues Adhaar cards in India.

Contact Hathway and ask them what they are doing to protect your data and compensate you for any damages or losses caused by the breach.

What is Hathway doing about the breach?

Hathway has not officially confirmed or commented on the breach yet. However, some sources suggest that the company is aware of the incident and is investigating it. It is unclear whether Hathway has notified its customers and employees about the breach or taken any measures to secure its systems and data.

The breach may have serious legal and regulatory implications for Hathway, as it may violate various laws and regulations related to data protection and privacy in India. These include the Information Technology Act 2000 (IT Act), the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules 2011 (IT Rules), and the Personal Data Protection Bill 2019 (PDP Bill).

The IT Act and the IT Rules require entities that collect, store, or process personal or sensitive data to implement reasonable security practices and procedures to protect the data from unauthorized access, disclosure, or misuse. They also require entities to obtain consent from the data subjects before collecting or using their data and to notify them in case of any breach.

The PDP Bill, which is yet to be passed by the Parliament, aims to establish a comprehensive framework for data protection and privacy in India. It proposes to create a Data Protection Authority (DPA) to oversee and enforce data protection laws and regulations. It also defines various rights and obligations for data subjects, data fiduciaries (entities that collect or process data), and data processors (entities that process data on behalf of data fiduciaries).

The PDP Bill also introduces the concept of 'data localization', which requires certain categories of data to be stored and processed only within India. This may affect Hathway's operations, as it may have to relocate its data centers or servers from other countries to India.

The breach may also expose Hathway to civil or criminal liabilities, as the data subjects may sue the company for negligence, breach of contract, breach of trust, or violation of their fundamental rights. The company may also face penalties or sanctions from the government or regulatory authorities for failing to comply with the applicable laws and regulations.

Conclusion:

The Hathway data breach is one of the largest and most serious data breaches in India's history. It affects millions of customers and employees of Hathway, as well as their families, friends, and associates. It also raises questions about Hathway's security practices and procedures, as well as its legal and regulatory compliance.

If you are a victim of the breach, you should take immediate action to protect yourself and your data from further harm. You should also demand accountability and transparency from Hathway and seek appropriate compensation or redress for any damages or losses caused by the breach.

Fetlla Logo
ServicesTrainingProductsBlogsEventsCertify itContact

© 2026 Fetlla LLP. All rights reserved.