EPCES Government Data Breach Exposes 68K Indian Trade Exporter Credentials
HEROIC's DarkHive system discovered the EPCES breach, exposing 67,979 records in August 2018. The Export Promotion Council for EOUs and SEZs, an official Indian government trade body, suffered a database compromise that revealed email addresses and plaintext passwords belonging to exporters, business owners, and trade professionals registered with this government portal.
Why This Is Dangerous
A breach of a government trade council portal is particularly serious because it exposes the credentials of business owners and exporters who may use the same passwords to access other government services, banking portals, and international trade platforms. Plaintext password storage in a government context represents a significant institutional security failure, as the passwords are immediately usable by any attacker who accesses the database without requiring any cracking effort. The business and government context of this user base elevates the downstream risk of corporate fraud and unauthorized government service access.
What Was Exposed
- Email Address
- Plaintext Password
Why This Matters
Business owners and exporters affected by this breach face targeted fraud risks including business email compromise, fraudulent trade documentation, and unauthorized access to export licensing systems. Government agency credential exposure is also a supply chain risk, as attackers can use compromised government portal accounts to intercept or manipulate official correspondence. Anyone who registered on the EPCES portal should immediately change their password on all platforms where the same credentials were used, particularly other government portals and business banking services.
How Database and Combolist Breach Works
Government web portals running on legacy infrastructure are particularly vulnerable to database attacks because security updates may be delayed due to procurement and compliance processes. Attackers exploit unpatched web application vulnerabilities or misconfigured database access controls to extract user records. Government portal credentials are especially valuable in combolists because many users reuse government registration passwords across financial and administrative platforms, providing attackers with potential access to sensitive business and government systems.
Check If You Are Affected
HEROIC offers a free identity scanner searching over 400 billion records including data from the EPCES breach. Visit heroic.com to check if your information was exposed.
Breach Breakdown
67,979 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds