A threat actor claims to have breached the National Informatics Centre (NIC), India’s government technology agency. The breach specifically targets the Kavach Authentication App, a two-factor authentication (2FA) tool developed by the NIC for securing access to government email services (like NIC/GOV) and other IT systems. The actor claims to have stolen 1.7 million records.
According to the threat actor, the compromised data from the Kavach app includes:
- User ID
- Password
- Seed
- sha256_key
- Backup code
- Private Keys
The actor also claims to be selling further access, including:
- Remote Code Execution (RCE)
- SMTP
- Bitbucket
- MSSQL
- AWS S3 Buckets












