This story is from May 05, 2016
Website not hacked, user data safe, confirms IRCTC
NEW DELHI: Indian Railway Catering and Tourism Corporation (IRCTC) has denied reports claiming that the e-ticketing portal of Indian Railways has been hacked. “We deny all reports claiming that IRCTC website was hacked. It is running perfectly fine,” IRCTC PRO Sandip Dutta told TOI Tech.
[UPDATE: No “Denial of Service attack” (DoS/DDoS) has been successful and the E-ticketing website has been working normally thereby eliminating any chances of unauthorized interference. Till now, leakage of data through none of the service providers of IRCTC has been established, according to IRCTC.]
The hacking speculations started after Maharashtra Cyber Cell was reportedly informed about a CD containing phone numbers, date of birth and other such information of IRCTC users being sold for Rs 15,000 in the market.
This raised fears about data of lakhs of IRCTC users being compromised.
"We have requested the state's Cyber Cell to provide us the data. Once we get the data, only then we can verify whether the data belongs to IRCTC or not,” said Dutta.
Dutta added, "The data can also belong to someone else and may be it is being sold in the market in the name of IRCTC to malign us.”
The IRCTC website is maintained by Centre for Railway Information Systems, which is a part of the Ministry of Railways.
There are also media reports claiming that Maharashtra government has identified the hackers who were selling these details.
Earlier, AK Manocha, managing director of IRCTC, told Mumbai Mirror that though there has been no official complaint regarding data hacking he has written to Delhi police's Cyber Cell to look into the matter.
IRCTC is India's largest e-commerce website. Lakhs of transactions take place daily on the website. Customers share details like PAN card, DoB, etc on it ile booking tickets.
Here is the official statement from IRCTC:The News Reports have appeared in some Electronic and Print media regarding alleged leakage of email and mobile numbers from user profile data of IRCTC E-ticketing system. Indian Railway Catering and Tourism corporation (IRCTC) is a PSU of Indian Railways. Its website irctc.co.in is used for purchasing Railway E-Tickets-ticketing system is managed in-house by CRIS, the IT arm of Indian Railways. The Data centre is in the premises of CRIS. As soon as the matter came to notice of Railways on 02/05/2016, thorough investigations were conducted to detect veracity of the news, however, no such incident has been detected by the technical teams of Centre for Railway Information Systems (CRIS) and Indian Railway Catering and Tourism Corporation (IRCTC).
No “Denial of Service attack” (DoS/DDoS) has been successful and the E-ticketing website has been working normally thereby eliminating any chances of unauthorized interference. About 5.48 lakh tickets were booked in a single day in April 2016 with 2.66 lakh peak concurrent users. About 13,600 tickets per minute were booked.
The E-ticketing system has several components viz., internet gateway, network security devices such as gateway router and Firewall, Application Delivery Controller, Security Information Event Management System (SIEM) web server and database server access logs. Each of the components has been checked and none of the components has been found to have unusual activity. Technical investigations have also not indicated any unusual activity with respect to various system components.
The IT security of E-ticketing system is ensured through regular security audits by Standardization Testing Quality Certification (STQC) directorate of Department of Electronics and IT, Government of India. The entire traffic flowing on E-ticketing system internet gateway is also forwarded to CERT-In in real-time for monitoring and alerting. The gaps reported by STQC in their penetration testing have been addressed. However, auditing is an ongoing process and security audit of E-ticketing system is undertaken biannually.
Audit trails are maintained for access to the system and all sensitive data like passwords etc are stored in encrypted form. In addition to this, 24x7 monitoring of the system is done throughout the year by technical team of experts. Strict physical checks are already in place in the Data centre like restricted access to Data centre, CCTV cameras at entry and exit points of Data centre.
The data of E-ticketing system can be broadly categorized into two categories viz., sensitive information like Debit/Credit Card details, Login ID, Passwords, which could cause potential financial risk. PAN card detail is not required for booking E-ticket. No sensitive data has been alleged to have been leaked.
It is clarified that other data like mobile number and email ids is available with a large number of electronic service providing entities viz., E-commerce firms, telemarketers etc. Email and mobile numbers have to be shared with service providers for providing catering services, cab services, hotel bookings, SMS services, etc. Till now, leakage of data through none of the service providers of IRCTC has been established.
A joint committee comprising of officers from both CRIS and IRCTC has been set up. The committee in their preliminary report has not found any indication of breach of security in any of the databases of the E‑ticketing system. Further investigations by this committee is in progress and once the purported leaked data is made available, further checks will be conducted.
Israel attacks Iran
- US-Israel Attack Iran Live Updates: US, Israel continue bombing in Iran; Israeli jets strike Hezbollah targets in Lebanon's Beirut
- Iran war: Hezbollah fires at Israel; US releases IRGC HQ strike video - 10 key points
- Watch: Israel uses Iron Beam to intercept rockets midair for first time — how it works
The hacking speculations started after Maharashtra Cyber Cell was reportedly informed about a CD containing phone numbers, date of birth and other such information of IRCTC users being sold for Rs 15,000 in the market.
This raised fears about data of lakhs of IRCTC users being compromised.
Read Also:
"We have requested the state's Cyber Cell to provide us the data. Once we get the data, only then we can verify whether the data belongs to IRCTC or not,” said Dutta.
The IRCTC website is maintained by Centre for Railway Information Systems, which is a part of the Ministry of Railways.
There are also media reports claiming that Maharashtra government has identified the hackers who were selling these details.
Earlier, AK Manocha, managing director of IRCTC, told Mumbai Mirror that though there has been no official complaint regarding data hacking he has written to Delhi police's Cyber Cell to look into the matter.
IRCTC is India's largest e-commerce website. Lakhs of transactions take place daily on the website. Customers share details like PAN card, DoB, etc on it ile booking tickets.
Here is the official statement from IRCTC:The News Reports have appeared in some Electronic and Print media regarding alleged leakage of email and mobile numbers from user profile data of IRCTC E-ticketing system. Indian Railway Catering and Tourism corporation (IRCTC) is a PSU of Indian Railways. Its website irctc.co.in is used for purchasing Railway E-Tickets-ticketing system is managed in-house by CRIS, the IT arm of Indian Railways. The Data centre is in the premises of CRIS. As soon as the matter came to notice of Railways on 02/05/2016, thorough investigations were conducted to detect veracity of the news, however, no such incident has been detected by the technical teams of Centre for Railway Information Systems (CRIS) and Indian Railway Catering and Tourism Corporation (IRCTC).
No “Denial of Service attack” (DoS/DDoS) has been successful and the E-ticketing website has been working normally thereby eliminating any chances of unauthorized interference. About 5.48 lakh tickets were booked in a single day in April 2016 with 2.66 lakh peak concurrent users. About 13,600 tickets per minute were booked.
The E-ticketing system has several components viz., internet gateway, network security devices such as gateway router and Firewall, Application Delivery Controller, Security Information Event Management System (SIEM) web server and database server access logs. Each of the components has been checked and none of the components has been found to have unusual activity. Technical investigations have also not indicated any unusual activity with respect to various system components.
The IT security of E-ticketing system is ensured through regular security audits by Standardization Testing Quality Certification (STQC) directorate of Department of Electronics and IT, Government of India. The entire traffic flowing on E-ticketing system internet gateway is also forwarded to CERT-In in real-time for monitoring and alerting. The gaps reported by STQC in their penetration testing have been addressed. However, auditing is an ongoing process and security audit of E-ticketing system is undertaken biannually.
Audit trails are maintained for access to the system and all sensitive data like passwords etc are stored in encrypted form. In addition to this, 24x7 monitoring of the system is done throughout the year by technical team of experts. Strict physical checks are already in place in the Data centre like restricted access to Data centre, CCTV cameras at entry and exit points of Data centre.
The data of E-ticketing system can be broadly categorized into two categories viz., sensitive information like Debit/Credit Card details, Login ID, Passwords, which could cause potential financial risk. PAN card detail is not required for booking E-ticket. No sensitive data has been alleged to have been leaked.
It is clarified that other data like mobile number and email ids is available with a large number of electronic service providing entities viz., E-commerce firms, telemarketers etc. Email and mobile numbers have to be shared with service providers for providing catering services, cab services, hotel bookings, SMS services, etc. Till now, leakage of data through none of the service providers of IRCTC has been established.
A joint committee comprising of officers from both CRIS and IRCTC has been set up. The committee in their preliminary report has not found any indication of breach of security in any of the databases of the E‑ticketing system. Further investigations by this committee is in progress and once the purported leaked data is made available, further checks will be conducted.
Top Comment
D
De Andre Jacobs
3470 days ago
Look they are real I have confirmed it, contact Alpha tunnel for your hack issues ranging from , University Grades change, Email and phone hack for text, whatsapp , call logs,Gps tracking including even Credit Report fix. He provides proof and trust me he''s real. Ive been ripped severaly they are very good and reliable or text them at 1 646 480 9658Read allPost comment
Popular from Business
- Middle East on the boil after Khamenei’s death: What does it mean for India’s trade, exports, crude oil & LPG supply?
- Gold, silver rate outlook: Will Middle East tensions trigger a fresh bullion rally? Here's what experts say
- Raising kids in this economy: To DINK or not? Why more Indian couples are rethinking parenthood
- Middle East tensions: Will stock market open lower on Monday? Analysts warn of volatility as crude rises
- EPFO may retain interest rate at 8.25% for FY 2026
end of article
Trending Stories
- FPIs pump Rs 22,615 crore into equities in February, highest inflow in 17 months
- Middle East tensions: Will stock market open lower on Monday? Analysts warn of volatility as crude rises
- India to shape global growth in coming decade: Shaktikanta Das
- GST collections rise to Rs 1.83 lakh crore in February, FY26 tally crosses Rs 20.27 lakh crore
- Crude oil prices in focus: OPEC+ increases output by 206,000 bpd amid Middle East tensions
- India’s basmati exports to be hit by Strait of Hormuz restrictions? Top 5 leading destinations from Middle East
- Auto demand stays firm as carmakers report higher February sales, strong retail momentum drive growth
Photostories
- Your evening habits might be slowing your metabolism: 5 must follow habits that will boost your digestion and help with weight loss
- Why so many Indians have borderline thyroid reports and ignore them: What you should do before it turns serious
- Exclusive - From Khanzaadi calling her ‘Criminal’ to vulgar gesture allegations and addressing Rajat Dalal as her brother; Chahat Pandey responds to ‘The 50’ drama
- 7 Therapist-approved techniques to communicate better with your partner
- South Delhi’s costliest streets: Where homes are valued in hundreds of crores
- Vegetarian foods that have more protein than fish: Experts reveal 6 foods and why they might be a healthier option
- Silent dehydration: 7 signs you might not be drinking enough water
- When love ends quietly: Why modern breakups are happening without drama
- 7 chicken starters you can make in just 15 minutes
- Vijay-Rashmika to Nupur-Stebin: Celeb couples celebrating first Holi 2026 as newlyweds
Up Next