Swachh Manch
We noticed a significant data dump appearing on a public Telegram channel on June 14, 2025, originating from the Swachh Manch platform. What struck us immediately was the sheer volume of records, exceeding 25 million user accounts, a substantial figure for a public-facing civic engagement initiative. The presence of readily usable credentials, even in hashed form, alongside personally identifiable information such as phone numbers and IP addresses, signals a high-value target for subsequent malicious activities. The nature of the compromised data suggests a direct database compromise rather than a more superficial web application vulnerability.
The breach, affecting 25,247,541 users of Swachh Manch, a digital platform facilitating citizen participation in cleanliness and sanitation initiatives across India, was discovered through its appearance on a Telegram channel. The compromised dataset contained a comprehensive array of user information including phone numbers, usernames, bcrypt password hashes, and IP addresses, along with associated dates. The source structure indicates a direct extraction from a core user database, bypassing typical application-level security measures. The implications are far-reaching, as this data can be leveraged for large-scale phishing campaigns, credential stuffing attacks against other services, and potentially for social engineering targeting individuals involved in civic activities. The inclusion of bcrypt hashes, while a step up from plain text, still presents a solvable challenge for attackers with sufficient computational resources, especially when combined with other leaked PII.
External Context
While specific news coverage directly detailing this particular Swachh Manch breach was not immediately apparent in mainstream outlets, the broader context of data breaches affecting government-linked or public service platforms in India is a recurring theme. OSINT investigations into similar incidents often reveal patterns of compromised credentials being traded on dark web forums and Telegram channels, underscoring the persistent threat landscape. Research from cybersecurity firms frequently highlights the vulnerabilities inherent in large, public-facing databases and the evolving sophistication of attackers in exploiting them. The Swachh Bharat Mission itself, being a high-profile national initiative, makes its associated platforms attractive targets for actors seeking to disrupt or exploit public trust.
Breach Breakdown
25,247,541 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds