• About WordPress
    • WordPress.org
    • Documentation
    • Learn WordPress
    • Support
    • Feedback
Skip to content
May 26, 2026
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Watchtower
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Vulnerability Report
Light/Dark Button
  • Home
  • News
  • Cyber Security
  • Hacker stole billing data from Power Company in India, ransomed for 10 million Rupees
  • Cyber Security

Hacker stole billing data from Power Company in India, ransomed for 10 million Rupees

Ddos March 31, 2018 2 minutes read

Last week, the Uttar Haryana Bijli Vitran Nigam (UHBVN) power company based in Panchkula, India, was hacked by an anonymous hacker organization. According to the information left by the attackers, after gaining access to UHBVN’s computer system, they invaded the billing system and successfully obtained UHBVN’s customer billing data. If UHBVN wants to regain this data, it will have to pay 10 million rupees (about $150,000) or equivalent Bitcoin as a ransom.

According to new Indian express reports, UHBVN is responsible for the electricity supply and cost collection in 9 major areas of Haryana (Panchkula, Ambala, Kurukshetra, Karnal, Panipat, Yamunanagar, Sonepat, Kaithal, and Rohtak) with over 260,000 customers (including Civil, commercial and industrial electricity).

The cyber attack occurred around 12:17 local time on the morning of March 21st. On the 22nd, UHBVN employees discovered that they had ransom information about the payment of ransom on their computer screens. UHBVN immediately investigated the matter.

The data stolen by hackers is the consumer bill of UHBVN customers. This includes the electricity bills that customers have paid, the number of unpaid electricity bills, and the customer’s address. The loss of data means that UHBVN will not be able to clearly understand which customers have not yet paid and the specific amount of electricity not paid. In addition, they can no longer view the customer’s electricity bill records.

A spokesman for UHVBN stated that after learning about the incident, they immediately contacted the police and a third-party security expert to jointly investigate the incident.

The spokesperson also stated that the databases stolen by hackers were encrypted and that customer-related data would not be compromised. In addition, UHVBN has a backup of this database and has been using backup for data recovery, so there will be no business interruption or loss.

UHVBN also emphasized that the company has taken many measures to phase out the billing systems currently in use and will replace it with a more technologically advanced cloud service system that will be operational by the end of May 2018. At present, the billing of about 4,000 customers for industrial electricity is already done through this system, so this attack is totally unaffected by these customers.

At present, we cannot yet assert whether the UHVBN official statement is true or trying to downplay the entire incident. But for the company, at least one thing is fortunate, that is, hackers just stole the data without causing substantial damage.

Rate this post

Support Our Threat Intelligence

If you find our CVE report and cybersecurity news helpful, consider supporting our work.

Buy Me a Coffee Logo Buy Me a Coffee PayPal
Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Share this article:

Facebook Post LinkedIn Telegram

Related posts:

  1. Hackers suddenly returned $20,000 to Coindash
  2. Malvertising Campaign Uses Fake Installers to Spread Oyster Backdoor
  3. EstateRansomware Exploits Veeam Vulnerability (CVE-2023-27532) in Sophisticated Attack
  4. SEO Poisoning: Unmasking the Malware Networks Behind Fake E-Commerce
  5. Russian APT UTA0355 Steals Microsoft 365 OAuth Tokens via Fake Security Conference Lures and WhatsApp Support
Tags: billing data

Search

Translation

CVE WATCHTOWER
🚨

Receive alerts for vulnerabilities being exploited in the wild.

⚑

Get notified instantly when a Proof of Concept (PoC) exploit is published.

πŸ”

Access critical info on vulnerabilities even when marked as "RESERVED".

🧠

Insights powered by decades of expertise and global intelligence sources.

🎯

Customize alerts with up to 10 keywords for your specific tech stack.

πŸ“Š

Export the raw CVE database for SIEM integration and reporting.

Upgrade Package

πŸ”΄ Live Critical Threats

  • CVE-2026-42773CVSS 9.3
    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
  • CVE-2026-42774CVSS 9.3
    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')...
  • CVE-2026-9478CVSS 9.8
    A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the...
  • CVE-2026-9477CVSS 9.8
    A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. This issue...
  • CVE-2026-9476CVSS 9.8
    A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the...
  • CVE-2026-9475CVSS 9.8
    A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. This affects the function...
  • CVE-2026-9458CVSS 9.8
    A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. The impacted element is...
  • CVE-2026-9457CVSS 9.8
    A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. The affected element is...
  • CVE-2026-9456CVSS 9.8
    A vulnerability was found in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function...
  • CVE-2026-9455CVSS 9.8
    A vulnerability has been found in Totolink A8000RU 7.1cu.643_b20200521. This issue affects...
Powered by CVE WATCHTOWER

Recent Zero-Day Vulnerabilities

  • Exploited in the Wild: Critical OWA Spoofing Flaw (CVE-2026-42897) Hits On-Premises Exchange Servers
  • Exploited in the Wild: Maximum CVSS 10 SD-WAN Flaw (CVE-2026-20182) Grants Admin Control
  • Exploited in the Wild: Critical 9.8 CVSS RCE Hits Canon GUARDIANWALL MailSuite
  • Exploit Code Released: Public PoC Dumps for Windows BitLocker Bypass and SYSTEM Elevation Zero-Days
  • Exploited in the Wild: “Dirty Frag” Linux Vulnerability Grants Instant Root Access
  • Under Active Attack: Ivanti EPMM Zero-Day Exploited in the Wild via Harvested Admin Credentials
Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • Disclaimer
    • Privacy Policy
    • DMCA NOTICE
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    Copyright Daily CyberSecurity Β© All rights reserved.