Hathway Breach: 5.5M Records, One ISP Leak, Many Attack Chains
HEROIC analysts identified a large dataset linked to Hathway, one of India's major internet service providers and digital TV operators, appearing on a prominent hacking forum on December 17, 2023. The breach exposed 5,496,256 records — a figure that places this among the most significant ISP data leaks documented by HEROIC that year. What makes this breach particularly serious is not just the volume, but the specific mix of data types: when an ISP leaks your IP address, phone number, username, email, full name, and hashed password together, each piece of information reinforces the next in a chain of risk that extends far beyond any single account.
One Breach, a Chain of Consequences: How Hathway Data Gets Weaponized
The Hathway dataset is a rare combination that gives attackers layered options for exploitation. First, the SHA1-hashed passwords can be cracked with modern tools and used for credential stuffing against email providers, banking apps, and any other service where the victim reused their password. Second, the leaked IP addresses allow attackers to map victims to their physical internet connections, which can be used to craft hyper-localized phishing messages or to identify targets in specific geographic zones. Third, phone numbers and full names enable SIM swapping attacks, where an attacker convinces a mobile carrier to transfer a victim's phone number to a new SIM, bypassing two-factor authentication. And finally, support ticket data — which was also included in the breach — may reveal sensitive account details, billing information, and records of prior security incidents. Each data type strengthens the next attack step in a chain that can lead to financial fraud, identity theft, and sustained account compromise.
What Was Exposed
- Email Address — 4.7 million unique addresses, primary attack vector for phishing
- Username — often reused across platforms, aids in account enumeration
- IP Address — links victims to physical locations and internet connections
- Phone Number — enables SIM swap attacks and targeted fraud calls
- First Name and Last Name — personalizes phishing and social engineering
- Password Hash (SHA1) — a weak hashing algorithm susceptible to modern cracking
Why ISP Breaches Carry Outsized Risk
When a social media platform or retailer is breached, victims can delete their accounts and move on. When an ISP is breached, the impact is structurally different. Your ISP holds information that is deeply tied to your physical identity and your home internet connection. IP address data, combined with a real name and phone number, allows attackers to build a profile that is accessable to anyone willing to pay for it on dark web marketplaces. Credential stuffing attacks launched using ISP credentials are also statistically more succesful because ISP accounts often share passwords with email and utility portals that users access infrequently and update rarely. This breach also exposed support ticket logs, which can reveal security questions, account recovery methods, and previously reported issues that attackers can exploit.
How Large-Scale Database Breaches Happen at ISPs
ISPs maintain massive customer databases to manage subscriptions, billing, technical support, and network authentication. These databases are high-value targets because they aggregate years of customer data in a single location. Attackers typically gain access through exploitation of internet-facing administrative interfaces, unpatched vulnerabilities in customer portal software, or compromised internal credentials. Once inside, they can exfiltrate millions of records before any automated alert triggers. The Hathway breach, classified as a database compromise, follows this pattern and reflects the systemic risk of large-scale centralized data storage without adequate segmentation and access controls.
Check If Your Information Was Exposed
HEROIC has catalogued the Hathway breach dataset within a database of over 400 billion records. If you are or were a Hathway customer in India, your email address, phone number, and password hash may be circulating on criminal platforms right now. Visit heroic.com to run a free check and find out if your personal data appears in this or any other known breach — then take immediate steps to update your passwords and secure your accounts.
Breach Breakdown
5,496,256 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds