[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f3rw4sohx59r24":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"modifiedDate":12,"contentUpdatedAt":13,"source":14,"sourceUrl":15,"sourceUrls":16,"pwnCount":22,"affectedCount":22,"affectedCountStatus":23,"affectedCountLowerBound":24,"affectedCountUnit":25,"hasEnglishDescription":4,"severity":26,"dataClasses":27,"description":33,"seoTitle":34,"seoTitleEn":35,"seoDescription":34,"seoDescriptionEn":36,"logoUrl":37,"isVerified":4,"isSensitive":38,"isSpamList":38,"isMalware":38,"company":39},"68e3266eda11adda4882533e","RailYatri","RailYatri Data Breach","railyatri","railyatri.in","2022-12-26T00:00:00.000Z","2023-12-05T07:17:53.000Z","2026-07-19T16:14:10.626Z","Verified online travel booking data breach","https:\u002F\u002Fwww.thehindu.com\u002Fbusiness\u002FIndustry\u002Ftrain-ticketing-platform-railyatri-hit-by-data-breach\u002Farticle66339367.ece",[15,17,18,19,20,21],"https:\u002F\u002Fthecyberexpress.com\u002Fthe-railyatri-data-breach-data-dump-dark-web\u002F","https:\u002F\u002Fcybersecuritynews.com\u002Frailyatri-data-breach\u002F","https:\u002F\u002Fwww.safetydetectives.com\u002Fblog\u002Frailyatri-leak-report\u002F","https:\u002F\u002Fwww.railyatri.in\u002F","https:\u002F\u002Fwww.railyatri.in\u002Fabout-us",23209732,"known",null,"unknown","Critical",[28,29,30,31,32],"Email addresses","Genders","Names","Phone numbers","Purchases","\u003Cp>A verified December 2022 breach of RailYatri exposed 23,209,732 unique email addresses. Data later released was claimed to contain more than 31 million customer rows and approximately 37,000 invoice records. The company said it detected the incident on December 28, identified the source, fixed it within hours, and notified authorities. Combining contact and ticket-purchase information increases the risk of travel-themed fraud.\u003C\u002Fp>\n\u003Ch2>Types of Exposed Data and Risks\u003C\u002Fh2>\n\u003Cp>\u003Cstrong>The five verified data classes are email addresses, genders, names, phone numbers, and purchase information.\u003C\u002Fstrong> The purchase class includes tickets bought and related travel and fare information. Combining a name, phone number, and ticket context can make fake booking confirmations, schedule changes, cancellations, refunds, or extra-fee messages more convincing. Gender information can add profile context for targeted social engineering. Passwords, payment cards, bank accounts, identity documents, and full physical addresses are not canonical data classes for this record.\u003C\u002Fp>\n\u003Ch2>Breach Timeline and Technical Details\u003C\u002Fh2>\n\u003Cp>The canonical breach date is December 26, 2022. RailYatri said it observed a security breach in its system on December 28, quickly established the source, fixed it within a few hours, and reported the incident to government authorities. The company said registered-user information such as age, email, preferred city, and phone number may have been viewed by unauthorized individuals, while no other sensitive customer information was compromised. In February 2023, data claimed to contain more than 31 million user rows and approximately 37,000 invoices was shared more widely. \u003Cstrong>More than 31 million raw customer rows and 23,209,732 unique email addresses are different measures.\u003C\u002Fstrong> The precise technical entry method was not publicly disclosed. This record must not be confused with the separate RailYatri server exposure in 2020 that affected about 700,000 people.\u003C\u002Fp>\n\u003Ch2>User Groups at Risk\u003C\u002Fh2>\n\u003Cp>People who bought a train or bus ticket through RailYatri during the affected period and used a real phone number face the most direct risk. Recent or frequent travelers may be more likely to trust fake support messages that resemble past ticket details. People who booked with a work email can face corporate phishing, while family or group bookings can support social engineering involving multiple passengers. Presence in the dataset does not mean that a payment card or account password was compromised.\u003C\u002Fp>\n\u003Ch2>Immediate Steps to Take\u003C\u002Fh2>\n\u003Cp>Do not follow links in unexpected booking, cancellation, refund, or schedule-change messages claiming to come from RailYatri, IRCTC, a rail operator, or a payment service; open the official website or application yourself. A message containing your ticket number, route, or name does not prove that the sender is legitimate. Reject requests for a one-time code, card detail, UPI PIN, account password, or identity document. Enable multi-factor authentication and login alerts on the email account, and review contact and recovery details on the RailYatri account. Verify unexpected booking changes through an official support channel.\u003C\u002Fp>\n\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\n\u003Cp>Use a unique password for every travel account and consider separating booking services with a dedicated email alias. Regularly review old tickets, saved passenger profiles, and contact information that is no longer needed, and use available data-deletion options. Keep transaction alerts enabled on email and financial accounts. Because travel dates and routes can reveal periods when a person is away from home, delay sharing this information on social media. For refunds or schedule changes, use a published contact channel instead of details provided in an incoming message.\u003C\u002Fp>\n\u003Ch2>Check Your Data\u003C\u002Fh2>\n\u003Cp>Check this record with the email address you used for RailYatri. \u003Cstrong>A match means the address appears in the verified 2022 RailYatri dataset; it does not show that a password, payment card, or identity document was exposed.\u003C\u002Fstrong> If the result is positive, independently verify travel-themed messages, strengthen email security, and review saved passenger information. If the result is negative, remember that it applies only to this dataset and does not cover the separate 2020 incident or other breaches.\u003C\u002Fp>","","RailYatri Data Breach (23.2 Million Reported Records)","RailYatri Data Breach. 23.2 Million reported records were reported. Reported data: Email addresses, Genders, Names. Review the scope, risks, and protective…","\u002Fuploads\u002Flogo\u002Frailyatri_in.webp",false,{"name":7,"sector":40,"country":41,"website":10,"websiteArchiveUrl":34,"websiteStatus":34,"websiteCheckedAt":24},"Online travel and ticketing","India"]