SQL Injection & Data Dumping
1. BigBasket Data Breach (2020)

Details:
- Attackers exploited an unsecured SQL file through SQL injection, accessing over 20 million users’ data.
- Stolen data, including email IDs, password hashes, and personal information, was sold on the dark web for approximately ₹30 lakh INR.
Investigation Steps:
- Detection: Breach identified after data appeared on the dark web.
- Acknowledgment: BigBasket confirmed the breach and filed a complaint with Bangalore Cyber Crime Cell.
- Forensic Analysis: Investigators analyzed compromised files to trace the breach’s origin.
- Dark Web Monitoring: Authorities monitored dark web forums for data distribution.
- User Notification: Affected users were informed to change passwords and secure accounts.