[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f234inruziugwb":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":7,"domain":9,"breachDate":10,"addedDate":11,"modifiedDate":12,"contentUpdatedAt":12,"source":13,"sourceUrl":14,"sourceUrls":15,"pwnCount":16,"affectedCount":16,"affectedCountStatus":17,"affectedCountLowerBound":18,"affectedCountUnit":19,"hasEnglishDescription":4,"severity":20,"dataClasses":21,"description":32,"seoTitle":33,"seoTitleEn":34,"seoDescription":33,"seoDescriptionEn":35,"logoUrl":36,"isVerified":4,"isSensitive":37,"isSpamList":37,"isMalware":37,"company":38},"68e3266eda11adda48825248","ixigo","ixigo Data Breach","ixigo.com","2019-01-03T00:00:00.000Z","2019-03-17T13:27:11.000Z","2026-07-29T17:31:54.033Z","Verified breach record","https:\u002F\u002Ftechcrunch.com\u002F2019\u002F02\u002F14\u002Fhacker-strikes-again\u002F",[14],17204697,"known",null,"email_identifiers","Critical",[22,23,24,25,26,27,28,29,30,31],"Auth tokens","Device information","Email addresses","Genders","Names","Passwords","Phone numbers","Salutations","Social media profiles","Usernames","\u003Cp>\u003Cstrong>The 2019 ixigo data breach\u003C\u002Fstrong> concerns an account dataset attributed to the India-based travel platform. The verified breach record dates the event to 3 January 2019 and reports 17,204,697 unique email addresses in the dataset. TechCrunch's 14 February 2019 report says the seller advertised approximately 18 million ixigo records as a listing separate from the other organizations offered for sale. The advertised row figure and verified unique-email count are different measures; they are neither added nor substituted for one another as a count of unique people.\u003C\u002Fp>\n\n\u003Cp>The verified structured fields are authentication tokens, device information, emails, genders, names, passwords, phones, salutations, social-media profiles, and usernames. The source says passwords were stored as MD5 hashes rather than plaintext; it does not disclose salting, so none is assumed. Token type, associated service, and validity at the incident date were not published either. Payment cards, bank accounts, travel itineraries, booking contents, passports, and government identifiers are outside the verified scope.\u003C\u002Fp>\n\n\u003Ch2>Incident and local-data boundary\u003C\u002Fh2>\n\u003Cp>The seller's decision to list several organizations in the same period does not establish one shared access method. Although reporting relayed a theory involving a common database flaw, public evidence does not confirm ixigo's initial entry vector. Production has no ixigo import job or locally linked email, password, username, phone, or person-level corpus. The 17,204,697 value is therefore retained as an external unique-email scope; \u003Ccode>totalRecords\u003C\u002Fcode> is not presented as a local total, and the import count is zero.\u003C\u002Fp>\n\n\u003Ch2>Privacy and safe response\u003C\u002Fh2>\n\u003Cp>This record does not prove that a particular person travelled, made a booking, had a token used, had a password recovered, or suffered account takeover. If a password used in 2019 still exists on another service, replace only the reused copies with unique passwords. Enable multi-factor authentication on the email account and verify ticket-change, refund, or account-verification messages through a known official channel. Knowledge of a real name, phone number, or profile link does not make a sender trustworthy.\u003C\u002Fp>","","ixigo 2019 Data Breach (17.2 Million Email Identifiers)","The ixigo breach contains 17,204,697 verified unique emails. Review the MD5 password hashes, ten data types, and local-data boundary.","\u002Fuploads\u002Flogo\u002Fixigo_com.webp",false,{"name":39,"sector":40,"country":41,"website":9,"websiteArchiveUrl":33,"websiteStatus":42,"websiteCheckedAt":43},"Le Travenues Technology Limited (ixigo)","Travel","India","active","2026-07-29T17:27:47.000Z"]