d’Katia Data Breach: 32,722 Records Exposed from Indian IT Services Firm (2023)
IT Services Firm Breach: d'Katia Exposes 32,000+ Records
When an IT services company suffers a data breach, the risk extends beyond its own customers. IT providers often have privileged access to client systems, networks, and data -- which means a breach at a provider can be a stepping stone into much larger organizations. In February 2023, d'Katia, an Indian IT services company, suffered a database breach exposing 32,722 records. The exposed data includng email addresses, usernames, hashed passwords, phone numbers, IP addresses, birthdays, and physical addresses represents one of the more complete PII dumps in this era -- and the presence of multiple hash types (bcrypt, SHA1, and MD5) signals particuarly inconsistent security practices across the platform.
d'Katia February 2023: Breach Summary
- Records Exposed: 32,722
- Data Types: Email addresses, usernames, password hashes (bcrypt, SHA1, MD5), phone numbers, IP addresses, birthdays, physical addresses
- Breach Type: Database
- Country Affected: India
- Date Leaked: February 4, 2023
The Mixed Hash Problem: Why Not All Hashed Passwords Are Equal
The d'Katia breach exposed passwords in three different hash formats: bcrypt, SHA1, and MD5. Bcrypt is a modern, intentionally slow hashing algorithm designed to resist brute-force cracking -- bcrypt passwords are difficult to crack even with significant computing resources. SHA1 is older and significantly weaker. MD5 is considered cryptographically broken: billions of MD5 hashes have been precomputed and stored in rainbow tables, allowing instant lookup of the original password without any cracking effort at all. Users whose passwords were stored as MD5 or SHA1 in the d'Katia breach should assume those passwords have been compromised, regardless of how complex they were, and change them on any service where they were reused.
IT Provider Breaches and the Supply Chain Risk
IT services companies that acesses client systems, manages cloud infrastructure, or provides technical support have visibility into environments far beyond their own organization. A breach that exposes employee credentials from an IT services firm can give attackers the usernames and passwords those employees use to log into client portals, remote management tools, and internal networks. Even if d'Katia's clients were not directly breached, any d'Katia employee whose reused password appeared in this breach represents a potential lateral entry point into client environments. This is the supply chain risk that makes IT provider breaches disproportionately dangerous relative to their raw record count.
Check If Your Data Was Exposed
HEROIC's free breach scanner searches across more than 400 billion exposed records -- including database breaches like d'Katia -- to tell you instantly if your email address has appeared in known data breaches. Run a free scan today at HEROIC.com.
Breach Breakdown
32,722 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds