The country's cybersecurity watchdog issued a security advisory after around 1,600 crore login credentials were exposed, including usernames, passwords, and authentication tokens from major online platforms.
The advisory recommends urgent action to mitigate the risk of unauthorized access, identity theft, and cyberattacks, suggesting measures like changing passwords, enabling multi-factor authentication, and updating systems to reduce malware risk.
The credential dataset was aggregated from various sources and primarily obtained through infostealer malware, exposing vulnerabilities in databases like unsecured Elasticsearch instances.
For individuals, the advisory suggests creating strong, unique passwords, activating MFA where available, and running antivirus scans. For organizations, enforcing multi-factor authentication, least-privilege access controls, and encrypting stored credentials are recommended.