Researchers Tie the PropTiger Breach to 2 Million Leaked Indian User Records
HEROIC analysts uncovered the PropTiger breach in early 2018, when a 3.46GB database file containing records for over 2 million Indian property seekers was exfiltrated from the platform. The exposed file included email addresses and phone numbers for 2,060,256 users. What is partcularly alarming is that this data resurfaced on a well-known hacking forum roughly two years after the initial incident, giving it a second life as a tool for targeted attacks against Indian consumers.
How Attackers Use Email Addresses and Phone Numbers Against You
When criminals get hold of both an email address and a phone number tied to the same person, the combination becomes a powerful weapon. They can launch highly convincing phishing emails that reference your real contact details, or use your phone number for SIM-swapping attacks that let them bypass two-factor authentication. Scammers in the real estate space are known to use leaked contact data to impersonate agents and brokers, making the PropTiger data seperate and especially valuable for fraud targeting property buyers in India.
What Was Exposed in the PropTiger Breach
- Email Address
- Phone Number
Why Real Estate Data Breaches Carry Long-Term Risk
Real estate customers share contact details at a particularly sensitive life stage, often while making large financial decisions. Criminals know this. Leaked PropTiger records have beleived to have been used to craft targeted property scams, fake investment offers, and loan fraud schemes aimed at Indian homebuyers. Even years after a breach, this type of data remains valuable because people rarely change their phone numbers or email addresses, meaning the information stays accurate and actionable for attackers long after the initial exposure.
How Database Breaches Work
A database breach happens when attackers find a way into the servers where a company stores its user information. This can happen through weak passwords on the database itself, unpatched software vulnerabilities, or an employee account that gets compromised. Once inside, attackers can copy the entire database and walk away with millions of records in minutes. The company may not even realize anything has been taken, since the original data is still sitting there untouched. The stolen records are then sold or shared on hacking forums, sometimes immediately and sometimes years later.
Check If Your Data Was Exposed
HEROIC's free breach scanner searches across more than 400 billion records to tell you instantly whether your email address or phone number appeared in the PropTiger breach or any other known data leak. Run a free check at HEROIC today and find out exactly what information about you is already in the hands of cybercriminals.
Breach Breakdown
2,060,256 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds