➽Data Leaks

Aditya Birla Fashion and Retail Ltd. (ABFRL) Hacked, Data Leaked

Jan 12, 2022
|
by Cybersecurity Analyst

Aditya Birla Fashion and Retail Ltd. (ABFRL) is a large conglomerate retail outlet with 3,212 retail stores throughout India and over 22,000 employees. It is a subsidiary of the Aditya Birla Group, which spans numerous sectors and has annual revenues of $45 Billion.

Aditya Birla Fashion & Retail Logo

On January 11, 2022 famous, due to previous loud cases, ShinyHunters hacking group has published on underground forum data concerning ABFRL.

In their supporting message hackers say: “We tried to get in touch with ABFRL. They sent a negotiator but he was just stalling (the offer was more than reasonable for a “US$ 45-Billion conglomerate”).
So we decided to leak everything for you guys including their famous divisions such as Pantaloons.com (https://facebook.com/pantaloons) or Jaypore.com (https://facebook.com/jaypore).”

Kaduu team acquired leaked files, size of which is already impressive: almost 200GB. We believe this data is truly taken from ABFRL, however company does not give an official statement.

Among the files we have found:

  • SQL databases concerning Jaypore.com, Limesurvey.org, Pantaloons.com, Flamingomom,
  • Exhaustive list of employees,
  • Allegedly Atos-made security reports.

Sensitive data of employees include:

PoornataID, HRStatus, PositionNumber, PositionTitle, HireDate, NameDisplay, NamePrefix, FirstName, MiddleName, LastName, BirthDate, BirthCountry, MaritialStatus, Gender, City, State, Postal, Emailid, ABGExperience, Age, Company, Business, BusinessUnit, Department, Location, JobBand, Designation, ReportsTo, SupervisorId, FunctionCd, FunctionDescription, SubFunction, SalaryGrade, HolidaySchedule, ManagerId, ManagerName, ManagerDesignation, ConfirmationDate, CostCentre, Religion, LastPromotionDate, Phone, Extension, Cadre, ManagerEmailId

According to DataBreaches.net “ShinyHunters informed that although they acquired customers’ credit card data with expiration date and CVV — and that ABFRL Pantaloons knows that ShinyHunters is in possession of such data, the firm has allegedly not informed customers about the breach of card data. If they have notified employees and customers privately of the data breach and exfiltration of data, DataBreaches.net has seen no proof of that as yet.”

💡 Do you think you're off the radar?

Your data might already be exposed. Most companies find out too late. Let ’s change that. Trusted by 100+ security teams.

🚀Ask for a demo NOW →
🛡️ Dark Web Monitoring FAQs

Q: What is dark web monitoring?

A: Dark web monitoring is the process of tracking your organization’s data on hidden networks to detect leaked or stolen information such as passwords, credentials, or sensitive files shared by cybercriminals.

Q: How does dark web monitoring work?

A: Dark web monitoring works by scanning hidden sites and forums in real time to detect mentions of your data, credentials, or company information before cybercriminals can exploit them.

Q: Why use dark web monitoring?

A: Because it alerts you early when your data appears on the dark web, helping prevent breaches, fraud, and reputational damage before they escalate.

Q: Who needs dark web monitoring services?

A: MSSP and any organization that handles sensitive data, valuable assets, or customer information from small businesses to large enterprises benefits from dark web monitoring.

Q: What does it mean if your information is on the dark web?

A: It means your personal or company data has been exposed or stolen and could be used for fraud, identity theft, or unauthorized access immediate action is needed to protect yourself.