2020 ImpactGuru — crowdfunding user database surfaced on dark web; vendor remediation
Data compromised
User and campaigner profile attributes including contact and account fields per dark-web listings analyzed by researchers and summarized in trade press
Technical writeup
Security research firms and Indian startup press described a large ImpactGuru user table circulating on criminal marketplaces in mid-2020, with field sets typical of fundraiser profiles and authentication metadata—prompting public incident acknowledgment narratives and renewed focus on pandemic-era charity fraud. Coverage alternated between roughly half-million-row samples in specialist threat blogs and broader reporting pairing the case with other Indian platform leaks.
Root cause
Unauthorized acquisition and resale of production or backup user data (exact intrusion chain not uniformly detailed across outlets)
References
- https://inc42.com/buzz/attack-on-crowdfunding-platform-impact-guru-highlights-covid-19-cyber-threats/
- https://cyble.com/blog/impact-guru-indias-leading-crowdfunding-platform-breached-500000-user-records-leaked-in-darkweb/
- https://www.technadu.com/religare-impact-guru-leaked-data-5-5-million-indians/128446/