HDFC Life Insurance reports data breach
Learn More
HDFC Life Insurance is reporting a data breach after an unknown threat actor leaked customer data. HDFC Life is one of India's leading life insurance company offering a range of individual and group insurance solutions that meet your various needs such as Protection, Pension, Savings and Retirement Plans.
The company is currently conducting a detailed investigation in consultation with information security experts to determine the root cause and implement necessary remedial actions. HDFC Life has initiated several response measures, including an information security assessment, data log analysis, and a root cause investigation.
Key details about the breach remain undisclosed, including the attack vector, number of affected individuals, types of exposed data, and financial impact.
HDFC has reported the incident to the regulators, and the regulatory body IRDAI is actively engaging with the affected companies and obtaining regular updates to ensure appropriate steps are taken to address the threat.
Update - as of 5th of December 2024, the stolen data of up to 16 million customers of HDFC is being sold on Dark Web forums. The breach has exposed highly sensitive customer information including:
- Policy numbers
- Full names
- Mobile phone numbers
- Email addresses
- Dates of birth
- Home addresses
- Health status information
The stolen data is being offered for sale at 200,000 USDT (Tether cryptocurrency) on the dark web, with records available in batches starting from 100,000 entries. CyberPeace investigation has revealed that a significant portion of the data has already been sold to various buyers.