4

Bulk extraction of citizen records from the Family ID registry

Database Activity Monitoring flagged a sustained sequence of large SELECT statements against classified personal-data tables from a service account, executed from a source host outside its normal pattern. Access Assurance had independently raised an anomalous authentication for the same account nineteen minutes earlier. Roughly 148,200 citizen records were read, including 6,410 records relating to children.

DischargesS.8(6)R.7S.8(4)
Acknowledgement
1 hour from becoming aware
Met· 07 Aug 2026, 01:19
Preliminary assessment
4 hours from becoming aware
Met· 07 Aug 2026, 03:43
Board notification
72 hours from becoming aware
--:--:--
Incident

Database Activity Monitoring

Reference
INC-2026-0042
Status
Investigating
Severity
Critical
Nature
exfiltration
Detected
07 Aug 2026, 00:19
Became aware
07 Aug 2026, 00:55
Contained
07 Aug 2026, 02:49
Lead
Rohit Verma
Affected sources
Family ID Core RegistryScheme Beneficiary Warehouse
Data categories
NameDate of birthGovernment identifierFamily IDPostal addressBank account
Impact

Assembled from the classified inventory. This is where discovery coverage becomes a breach-response capability.

1.48 L
Data Principals affected
Children affected
6.41 K
Elements exposed
14
Indicative exposure
₹250 Cr
R.7S.8(6)S.9

Response tasks — 6 of 16 complete

Grouped by phase. Mandatory tasks are the ones a regulator will ask you to evidence.

Triage
Containment
Impact assessment
Notification
Remediation
Review
Notification to the Data Protection Board of India

Rule 7(2) prescribes the content: the nature, extent and timing of the breach, its likely consequences, the mitigation measures taken, the remedial measures to prevent recurrence, and the status of notification to Data Principals.

initial drafted

Nature, extent and timing

Unauthorised access to and extraction of personal data from the Family ID Core Registry and the Scheme Beneficiary Warehouse, between 02:14 and 03:47 IST, affecting approximately 148,200 Data Principals of whom 6,410 are children. Access was obtained through a compromised service account credential.

Likely consequences

Risk of identity misuse and targeted fraud against affected Data Principals, particularly where government identifier references and bank account details were included. Elevated risk to the 6,410 affected children.

Mitigation measures taken

The service account was suspended and all active sessions terminated within 46 minutes of detection. Source host network access was revoked. Credential rotation has been completed across all service accounts with access to classified tables.

Remedial measures

Break-glass approval will be required for all service-account access to classified personal-data tables. Mass-read thresholds have been lowered. A full entitlement review of service accounts has been initiated.

Data Principal notification status

Notification content drafted in Hindi and English; dispatch pending DPO approval.

Not yet filed. Filed by the Data Protection Officer.
Every action in this war-room is written to the immutable audit trail with the actor and timestamp — that record is what makes the response defensible later.Audit trail