The BSNL Breach Happened in 2014. The Passwords Are Still Exposed
HEROIC analysts logged this breach from Bharat Sanchar Nigam Limited (BSNL), the Indian state-run telecommunications provider, dated June 28, 2014. The exposed data set contains 4,875 records made up of email addresses and passwords that were stored in plaintext, meaning no hashing or encryption was ever applied to protect them.
Why the BSNL Breach Is Dangerous
Plaintext passwords are the worst case in any data breach. There is no cracking or decrypting required. Anyone who gets a copy of this data can read the password sitting right next to the email address and use it immediately, on the original account or anywhere else that same password was reused.
What Was Exposed in the BSNL Breach
- Email addresses
- Passwords stored in plaintext
Why the BSNL Breach Matters
Most people reuse passwords across more than one account. When a plaintext password tied to an email address gets exposed, attackers routinely test that exact combination against email providers, banking apps, and social media in a process called credential stuffing. If it works anywhere else, the result is account takeover, and from there, identity theft or financial fraud become possible.
How the BSNL Data Was Exposed
This incident is classified as a database breach, meaning attackers gained direct access to BSNL's backend systems and extracted a table of user records rather than harvesting credentials one at a time. Database breaches like this one typically stem from an unpatched vulnerability, a misconfigured server, or a flaw that let an attacker query and export data they were never meant to see. Once exported, the data gets packaged and circulated on forums and marketplaces where other criminals can buy or trade it.
Check If You Were Affected by the BSNL Breach
If you ever had an account tied to BSNL, it is worth checking whether your email address shows up in this incident. HEROIC's free breach scanner searches a database of more than 400 billion leaked records, including this one, so you can see your exposure and take action, like changing any reused passwords, before someone else does.
Breach Breakdown
4,875 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds