Skip to content
June 20, 2026
  • Linkedin
  • Twitter
  • Facebook
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Watchtower
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Vulnerability Report
Light/Dark Button
  • Home
  • News
  • Data Leak
  • Hackers successfully penetrated BSNL intranet, over 47,000 employees info were leaked
  • Data Leak

Hackers successfully penetrated BSNL intranet, over 47,000 employees info were leaked

Do Son March 6, 2018 3 minutes read
BSNL intranet
Add as a preferred
source on Google

According to The Economic Times (ET) and ciol reports, French security researcher Robert Baptiste claims to have obtained access to the internal network database of India‘s state-owned telecommunications operator Bharat Sanchar Nigam Limited (BSNL), the database contains details of more than 47,000 employees.

Baptiste contacted ET via e-mail and told ET that he got BSNL’s internal network through a security hole and embed malicious code in the software used by BSNL to gain access to the database.

On Sunday morning, Baptiste also shared with ET a database of samples detailing BSNL’s departure and current employee name, job title, password, phone number, date of birth, retirement date, email address and more. ET then retrieved the personal information of six employees from the database and verified their identities by phone.

Baptiste also said there are security holes in multiple sites under the domain name of BSNL, making them extremely vulnerable to SQL injection attacks. In fact, there are already two BSNL websites that have been subjected to ransomware attacks, but the exact time of the attacks on the websites is not yet clear and the website has now been forced to go offline.

Baptiste also found that up to eight other BSNL sites have an open directory that allows anyone to access the database. He had contacted BSNL via Twitter on Sunday afternoon and informed them about the issue. The company’s IT team discussed with him and finally confirmed the seriousness of the problem. Currently, most of the vulnerabilities have been fixed, and some websites have also been deleted.

“I found this a few days ago, but I’m not the first one to discover it. This issue was discovered by an Indian, kmskrishna, two years ago. He sent mails to BSNL, even called senior officers, but nobody answered him. Once again, it shows the importance for big companies like BSNL to take into account this kind of alert.” , Baptiste said.

1) There was a SQL injection in their intranet website. It allows the attacker to dump the all database of the BSNL intranet. It contains the information of 47K+ BSNL employees, Senior officiers' information, BNSL administrators information, retired employee details and more. pic.twitter.com/HTEwtC63wp

— Baptiste Robert (@fs0c131y) March 4, 2018

Due to the current lack of data protection laws in India, this hacking activity is governed by the Indian Information Technology Act of 2000. Pursuant to the act, it is a criminal offense to intrude into a computer system for whatever purpose or in any way that an individual may be subject to criminal charges.

Baptiste said “A monitoring bandwidth system was accessible publicly. BSNL websites had a lot of open directories which allowed everybody to consult their documents. Some sites are down, and some are fixed. calcutta.bsnl.co.in has been fixed.”

Related coverage

  • The Dark Side of ChatGPT: Trade Secret Leaks in Samsung
  • Microsoft denied that 30 million Microsoft account information had been compromised
  • Red Hat Confirms Breach of GitLab Instance, Customer Network Blueprints Stolen
  • 200 million Japanese netizens’ personal data offered on the underground market
  • The Vanishing Act: Apple Forces GitHub to Delete 8,270 Repositories of Leaked App Store Code

Support Our Threat Intelligence

If you find our CVE report and cybersecurity news helpful, consider supporting our work.

Buy Me a Coffee Logo Buy Me a Coffee PayPal
Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Share this article:

Facebook Post LinkedIn Telegram
Written by
@DdoS · Security Researcher

Do Son

Do Son is the Founder and Editor of SecurityOnline.info. Working in cybersecurity since 2013, he reports on vulnerabilities, malware, and emerging threats, providing timely analysis to help organizations and individuals stay ahead of evolving risks.

Tags: BSNL intranet

Search

Translation

CVE WATCHTOWER
🚨

Receive alerts for vulnerabilities being exploited in the wild.

⚡

Get notified instantly when a Proof of Concept (PoC) exploit is published.

🔍

Access critical info on vulnerabilities even when marked as "RESERVED".

🧠

Insights powered by decades of expertise and global intelligence sources.

🎯

Customize alerts with up to 10 keywords for your specific tech stack.

📊

Export the raw CVE database for SIEM integration and reporting.

Upgrade Package

🔴 Live Critical Threats

  • CVE-2026-5366CVSS 9.9
    Prefect version 3.6.23 is vulnerable to remote code execution due to improper...
  • CVE-2024-58351CVSS 9.8
    Flowise before 2.1.4 allows configuration to be injected into the Chainflow during...
  • CVE-2022-50972CVSS 9.8
    WooCommerce 7.1.0 contains a remote code execution vulnerability that allows attackers to...
  • CVE-2019-25763CVSS 9.8
    WordPress Ultimate Addons for Beaver Builder 1.2.4.1 contains an authentication bypass vulnerability...
  • CVE-2026-11551CVSS 9.8
    The Branda plugin for WordPress is vulnerable to privilege escalation via account...
  • CVE-2026-56081CVSS 9.1
    Cap-go before 12.128.2 contains an authentication logic flaw that lets an attacker...
  • CVE-2026-56073CVSS 9.4
    Cap-go before 12.128.2 contains an authentication bypass vulnerability in OTP verification that...
  • CVE-2026-55447CVSS 9.6
    ### Summary All components based on `BaseFileComponent` are vulnerable to the following...
  • CVE-2026-48584CVSS 9.9
    Execution with unnecessary privileges in Azure Synapse allows an authorized attacker to...
  • CVE-2026-48582CVSS 9.6
    Missing authorization in Microsoft Exchange Online allows an authorized attacker to elevate...
Powered by CVE WATCHTOWER

Recent Zero-Day Vulnerabilities

  • GreatXML BitLocker Bypass: Public PoC Exploit Disclosed
  • Check Point VPN Vulnerability Exploited in the Wild with Ransomware Links
  • Weekly Threat Intelligence: June 1 to June 7, 2026
  • Cisco SD-WAN Vulnerability Exploited in the Wild with Root RCE Risks
  • Android Zero-Day Flaw Exploited in the Wild: June 2026 Patches Released
  • Exploited in the Wild: Critical OWA Spoofing Flaw (CVE-2026-42897) Hits On-Premises Exchange Servers
Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • Disclaimer
    • Privacy Policy
    • DMCA NOTICE
    • Linkedin
    • Twitter
    • Facebook
    • Youtube
    © 2017 - 2026 Daily CyberSecurity. All Rights Reserved.