Bulk extraction of citizen records from the Family ID registry
Database Activity Monitoring flagged a sustained sequence of large SELECT statements against classified personal-data tables from a service account, executed from a source host outside its normal pattern. Access Assurance had independently raised an anomalous authentication for the same account nineteen minutes earlier. Roughly 148,200 citizen records were read, including 6,410 records relating to children.
Database Activity Monitoring
- Reference
- INC-2026-0042
- Status
- Investigating
- Severity
- Critical
- Nature
- exfiltration
- Detected
- 07 Aug 2026, 00:19
- Became aware
- 07 Aug 2026, 00:55
- Contained
- 07 Aug 2026, 02:49
- Lead
- Rohit Verma
- Affected sources
- Family ID Core RegistryScheme Beneficiary Warehouse
- Data categories
- NameDate of birthGovernment identifierFamily IDPostal addressBank account
Response tasks — 6 of 16 complete
Grouped by phase. Mandatory tasks are the ones a regulator will ask you to evidence.
Rule 7(2) prescribes the content: the nature, extent and timing of the breach, its likely consequences, the mitigation measures taken, the remedial measures to prevent recurrence, and the status of notification to Data Principals.
Nature, extent and timing
Unauthorised access to and extraction of personal data from the Family ID Core Registry and the Scheme Beneficiary Warehouse, between 02:14 and 03:47 IST, affecting approximately 148,200 Data Principals of whom 6,410 are children. Access was obtained through a compromised service account credential.
Likely consequences
Risk of identity misuse and targeted fraud against affected Data Principals, particularly where government identifier references and bank account details were included. Elevated risk to the 6,410 affected children.
Mitigation measures taken
The service account was suspended and all active sessions terminated within 46 minutes of detection. Source host network access was revoked. Credential rotation has been completed across all service accounts with access to classified tables.
Remedial measures
Break-glass approval will be required for all service-account access to classified personal-data tables. Mass-read thresholds have been lowered. A full entitlement review of service accounts has been initiated.
Data Principal notification status
Notification content drafted in Hindi and English; dispatch pending DPO approval.