Security

Indian Railways suffers unspecified security 'breaches in various IT applications'

13m passengers a day, a million tickets bought on digital platforms, and yet few details offered on what went wrong


Indian Railways has revealed it has suffered "a number of incidents... regarding breaches in various IT applications" and appears to have blamed some of them on sloppy infosec practices among staff working from home due to the COVID-19 pandemic.

The organisation's document [PDF] announcing the cyber-transgressions says "a majority of these are application related," but doesn't explain what applications were affected nor the extent of the intrusions.

Which is a little scary as Indian Railways says it has 1.54 million people on the payroll, serves 13 million passengers a day, and about a million of those book tickets using what the organisation describes as "computerised reservation facilities." The organisation is known to operate an intranet, a Freight Operations Information System, and almost certainly many more applications besides. The Register would be surprised if it does not have a fabulous tangle of legacy systems and more modern kit.

UK govt finds £200,000 under sofa to kick off research into improving mobile connectivity on nation's crap railways

READ MORE

And then there's the 108,000km of tracks, 6,853 stations, and 11,000-plus daily services the organisation operates.

India requires government organisations to file data security breach reports, though they are not made public. The Register has asked Indian Railways to explain what applications were compromised, and if these break-ins resulted in any risk to the public. We will update this story if we receive a substantive response.

Indian Railways has tied some of the incidents to "improper handling of the IT assets by the personnel in general," and said the security incidents have increased "as electronic working gets further proliferated." Staff have been ordered to undergo infosec training to ensure they don't place the organisation at further risk. ®

Send us news
14 Comments

India and EU finally advance HPC collaboration project hatched in 2022

Seek ideas for thorny problems related to both HPC and real-world problems

Use of India's CBDC declines, but central bank presses ahead

Work to make the digital rupee programmable has begun

Apple stops warning of 'state-sponsored' attacks, now alerts about 'mercenary spyware'

Report claims India's government, which is accused of using Pegasus at home, was displeased

India's Uber clone Ola Cabs hails ride out of the international market

Australian drivers given two days' notice, UK and New Zealand services also shuttered

Vigorous US lobbying reportedly reversed India PC import license scheme

Washington was most displeased and New Delhi knew it made a mistake

Indian court halts operations of government-run social media fact checker

Rights groups protested potential for sneaky censorship of political rivals

India's competition regulator orders Google Play payment probe

Choice of alternative payment providers labelled 'illusory' – because none existed

India celebrates rapid adoption of its internet of livestock

Latest piece of digital public infrastructure is positively beastly

India quickly unwinds requirement for government approval of AIs

Also: US woos Thailand, Philippines, for tech trade; China's Fukushima rage glows; Alibaba targets South Korea

Dirty data shocks Indian taxpayers with huge bills

Extra zeroes added to transaction values, just a handful of days before a payment deadline

India plans 10,000-GPU sovereign AI supercomputer

Puts $1.2 billion on the table for AI skills and local LLMs, tells private enterprise it expects help

Indian tech minister vows to stop Google removing local apps from Play Store

PLUS: APNIC director general to step down; Hong Kong's odd cloud survey; Rent-a-friend online in China; and more