EPCES Data Breach Exposes 67,979 Indian Trade Council Records
HEROIC's DarkHive intelligence system discovered the EPCES data breach, exposing 67,979 records in August 2018. EPCES is the Export Promotion Council for Export Oriented Units and Special Economic Zones, an official body under India's Ministry of Commerce and Industry. The compromised data included email addresses and plaintext passwords, representing a serious security failure at a government-affiliated trade organization.
Why This Is Dangerous
Government and quasi-governmental organizations like EPCES attract members and users including exporters, business owners, and trade professionals who often use their official business email addresses for registration. Plaintext password storage means there is zero protection for user credentials, and attackers can immediately use them to access email accounts, banking portals, and government trade systems. Business email accounts compromised through this breach can be used to conduct business email compromise fraud against trading partners.
What Was Exposed
- Email Address
- Plaintext Password
Why This Matters
Exporters and business owners registered with EPCES may use the same credentials for other government portals, banking services, and business software. Credential stuffing attacks using these plaintext passwords can give attackers immediate access to sensitive business accounts. Identity theft using exposed business email addresses can also enable fraudulent trade documentation and financial transactions, causing direct financial harm to affected businesses in India's export sector.
How Database Breaches Work
A database breach occurs when attackers exploit vulnerabilities such as SQL injection flaws, insecure direct object references, or poor access controls to extract data from a website's backend database. The decision to store passwords in plaintext rather than hashing them with a secure algorithm like bcrypt or Argon2 is a fundamental security failure that dramatically amplifies the harm caused when a breach occurs. Stolen databases from government trade portals are particularly valuable on dark web markets because the business contact data within them can be used for targeted business fraud.
Check If You Are Affected
HEROIC offers a free identity scanner searching over 400 billion records including data from the EPCES breach. Visit heroic.com to check if your information was exposed.
Breach Breakdown
67,979 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds