[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f22cq91p0bl7qx":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"modifiedDate":12,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":19,"affectedCount":19,"affectedCountStatus":20,"affectedCountLowerBound":21,"affectedCountUnit":22,"hasEnglishDescription":4,"severity":23,"dataClasses":24,"description":32,"seoTitle":33,"seoTitleEn":34,"seoDescription":33,"seoDescriptionEn":35,"logoUrl":36,"isVerified":4,"isSensitive":37,"isSpamList":37,"isMalware":37,"company":38},"68e3266eda11adda4882510e","bigbasket","bigbasket Data Breach","bigbasket.com","2020-10-14T00:00:00.000Z","2021-04-26T04:00:10.000Z","2021-04-26T06:15:01.000Z","2026-07-19T15:38:09.348Z","Online grocery customer data breach","https:\u002F\u002Findianexpress.com\u002Farticle\u002Fbusiness\u002Fbusiness-others\u002Fbigbasket-data-breach-user-details-leaked-dark-web-cyber-crime-7009578\u002F",[15,17,18],"https:\u002F\u002Fm.thewire.in\u002Farticle\u002Ftech\u002Fbigbasket-data-breach-details-20-million-users-dark-web","https:\u002F\u002Fwww.bigbasket.com\u002F",24500011,"known",null,"unknown","Critical",[25,26,27,28,29,30,31],"Dates of birth","Email addresses","IP addresses","Names","Passwords","Phone numbers","Physical addresses","\u003Cp>An October 2020 breach affecting bigbasket customer data exposed 24,500,011 unique email addresses. Data from the India-based online grocery service was first offered for sale and then shared publicly in April 2021. Combining delivery and account details increases the risk of phishing, fake order notices, and account takeover based on password reuse.\u003C\u002Fp>\n\u003Ch2>Types of Exposed Data and Risks\u003C\u002Fh2>\n\u003Cp>\u003Cstrong>The verified data classes are dates of birth, email addresses, IP addresses, names, passwords, phone numbers, and physical addresses.\u003C\u002Fstrong> This combination can help attackers use a real name, contact details, and delivery context to create fake shipment, order-cancellation, refund, or address-update messages. Passwords were not in plain text; they used the legacy Django(SHA-1) hash format, which does not meet modern password-storage expectations and does not eliminate offline guessing risk for weak passwords. Payment cards and bank accounts are not verified data classes for this record.\u003C\u002Fp>\n\u003Ch2>Breach Timeline and Technical Details\u003C\u002Fh2>\n\u003Cp>The canonical breach date is October 14, 2020. Near the end of October 2020, a database said to be about 15 GB and contain close to 20 million customer rows was offered for sale. In November 2020, bigbasket said it was evaluating a potential data breach, investigating the scope with security specialists, and had filed a complaint with the Bengaluru Cyber Crime Cell. The company also said it did not store financial data or card numbers. The data was shared more broadly in April 2021, and canonical analysis verified 24,500,011 unique email addresses. \u003Cstrong>The initial estimate of nearly 20 million rows and the 24,500,011 unique email addresses are not the same measure or the same stage of analysis.\u003C\u002Fstrong> The precise technical entry method was not publicly disclosed.\u003C\u002Fp>\n\u003Ch2>User Groups at Risk\u003C\u002Fh2>\n\u003Cp>Customers who had a bigbasket account and shared a phone number or delivery address during the affected period face the most direct risk. Anyone who reused the same password on email, shopping, payment, or work accounts is more exposed to password-reuse login attempts. Combining a name, phone number, birth date, and address can make fake customer-support calls and delivery-themed messages more convincing. An IP address does not reveal an exact location by itself, but it can add context for account linking and targeting when combined with other profile fields.\u003C\u002Fp>\n\u003Ch2>Immediate Steps to Take\u003C\u002Fh2>\n\u003Cp>If a password used with bigbasket during the breach period is still used on any account, change it immediately and retire similar variations. Secure the email account first, review active sessions and recovery options, and enable multi-factor authentication where supported. Do not open links sent under the pretext of an order, coupon, refund, payment correction, or address update; open the known website or official application yourself. A message containing your real name, phone number, or address does not prove the sender is legitimate, and one-time verification codes should never be shared.\u003C\u002Fp>\n\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\n\u003Cp>Use a password manager to generate a different password for every service, and separate shopping accounts with dedicated email aliases where practical. Remove delivery addresses and phone numbers from old accounts that are no longer used, and keep account-recovery details current. Leave login alerts enabled for email and financial accounts, and verify unexpected password-reset or order notifications through an independent channel. Because hard-to-change details such as addresses and birth dates can support social engineering years later, do not treat this incident as a risk resolved by a one-time password change.\u003C\u002Fp>\n\u003Ch2>Check Your Data\u003C\u002Fh2>\n\u003Cp>Check this record with the email address you used for bigbasket. \u003Cstrong>A match means the address appears in the canonical bigbasket dataset; it does not mean that payment-card or bank information was exposed.\u003C\u002Fstrong> If the result is positive, replace the old password everywhere it was reused, prioritize email security, and watch for delivery-themed scams. If the result is negative, remember that it applies only to this dataset and does not rule out exposure in other breaches.\u003C\u002Fp>","","bigbasket Data Breach (24.5 Million Reported Records)","bigbasket Data Breach. 24.5 Million reported records were reported. Reported data: Dates of birth, Email addresses, IP addresses. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Fbigbasket_com.webp",false,{"name":7,"sector":39,"country":40,"website":9,"websiteArchiveUrl":33,"websiteStatus":33,"websiteCheckedAt":21},"Online grocery and e-commerce","India"]