🚨 Alleged CAG India Website Compromise — Database, Admin Panel & Web Shell Offered for Sale
CyberRakshakLabs analyzes an alleged dark-web claim involving cag.gov.in, an apparent CAG administrative interface, and claims of database and web-shell access; compromise scope remains independently unverified.
{inline(s["title"])}
A newly observed dark-web listing claims that an attacker compromised the Comptroller and Auditor General of India (CAG) website and is offering a combination of:
Database access Administrative panel access Web shell Alleged access to the CAG web infrastructure
The listing shown in your screenshot was marked as discovered on:
2026-10-02 02:24:05 UTC The attacker claims that a weakness in cag.gov.in was exploited and provides a screenshot as alleged proof.
The supplied proof screenshot appears to show:
The CAG website. An apparent injected message displayed over the website. An administrative interface. An account/office context associated with Accountant General (A&E), Mizoram, Aizawl. A URL structure containing /admin.
However, the screenshots alone do not prove that the attacker obtained the complete CAG database, persistent web-shell access, or unrestricted administrative control.
This distinction is extremely important.
Current assessment:
A new compromise claim exists. Evidence of an apparent website/admin compromise is presented by the threat actor, but database theft and web-shell access remain unverified.
{inline(s["title"])}
The first screenshot is a threat-intelligence listing titled:
“Alleged hack of Comptroller and Auditor General of India with database, admin panel and web shell offered for sale”
The listing claims:
Target
cag.gov.in
Claim
The attacker says they exploited a weakness in the CAG website.
Assets allegedly offered
Database Admin panel Web shell
Price
$300
Proof
The actor provides a screenshot hosted under the CAG domain as alleged evidence.
Discovery timestamp
The listing records:
2026-10-02T02:24:05.000Z
That corresponds to approximately 07:54 AM IST on 2 October 2026.
{inline(s["title"])}
The second image is particularly interesting.
It appears to show the CAG website with a large attacker-controlled overlay containing a repeated string associated with the actor.
The screenshot also appears to show an administrative interface containing:
Accountant General (A&E), Mizoram, Aizawl and multiple administrative functions.
This is potentially more significant than a simple website defacement claim because it suggests that the actor may have reached an authenticated administrative application.
However:
What it proves It demonstrates that the actor has produced a screenshot showing what appears to be:
CAG website + administrative interface + attacker-controlled content
What it does NOT prove
It does not independently prove:
Complete database exfiltration Database contents Web-shell execution Persistence Root/server access Access to all CAG subsites Access to internal systems Access to employee credentials Access to audit records outside the affected application Destruction or modification of official records
Those require independent validation.
{inline(s["title"])}
There is a very interesting piece of background information in CAG's own public documentation.
A CAG functional-requirements document describes its existing website architecture as having approximately 140 subsites, with a CMS used for content management and administrative access.
The document describes an older technology stack including:
RHEL 7.1 Apache 2.4.6 PHP 7.2.24 MySQL 5.6.38 CakePHP 3 CAG CMS
The document explicitly describes this technology as outdated and calls for development/upgrading to a newer platform. It also specifies requirements for role-based access and stronger authentication, including 2FA for certain administrative access. Comptroller and Auditor General of India
Why this matters This does not prove that the current 2026 attack resulted from the old technology stack.
But it establishes an important historical attack-surface context:
It should examine the entire CMS and subsite architecture.
{inline(s["title"])}
During my verification, the official CAG website was reachable and serving its normal website content.
The current site contains the expected CAG sections including audit reports, offices, accounts, resources and media content. It also contains 2026 material, including recent events and publications. Comptroller and Auditor General of India
For example, a CAG subsite page currently shows content updated in September 2026. Comptroller and Auditor General of India
Important conclusion
The fact that:
cag.gov.in is currently operational does not invalidate the dark-web claim.
An attacker could have:
obtained temporary access, accessed an administrative subsystem, uploaded files, modified a particular subsite, subsequently lost access, or fabricated some evidence.
Therefore:
Website currently online ≠ no compromise.
{inline(s["title"])}
There are three separate claims here.
Level 1 — Website compromise The screenshot appears to show attacker-controlled content on the CAG website.
Status: Potentially credible, but independently unverified.
Level 2 — Administrative access The screenshot appears to show an administrative panel.
Status: Stronger indicator, but still requires validation that the screenshot was generated from an actually authenticated session rather than a fabricated image or publicly accessible interface.
Level 3 — Database + Web Shell The actor claims both are for sale.
Status: Unverified.
This is the most important distinction for your CyberRakshakLabs article.
{inline(s["title"])}
Based on the available evidence, a hypothetical attack chain could look like:
The initial vulnerability and exact exploitation mechanism are unknown.
{inline(s["title"])}
At this stage, these should be treated as investigation hypotheses, not conclusions:
{inline(s["title"])}
If the web-shell claim is genuine, the incident becomes significantly more serious than a simple defacement.
A PHP web shell could potentially provide:
database credentials API keys SMTP credentials application secrets encryption keys session secrets
Again, these are potential capabilities, not confirmed actions in this incident.
{inline(s["title"])}
If the database claim is genuine, investigators should determine exactly what database was accessed.
Possible categories could include:
CMS users administrative accounts user metadata audit-related content website content application configuration contact information internal administrative records session information
But we currently do not have verified evidence showing what data, if any, was actually exfiltrated.
Therefore your public article should avoid statements such as:
“CAG's entire database was leaked.”
Instead:
“A threat actor claims to have obtained and is offering a CAG database for sale; the authenticity, scope and provenance of the alleged database have not been independently verified.”
{inline(s["title"])}
The second screenshot should be examined from a DFIR perspective.
Investigators should extract:
URL Identify the exact administrative URL shown.
Timestamp Determine when the screenshot was generated.
User/session Determine which account is displayed.
Office
The screenshot appears to reference:
Accountant General (A&E), Mizoram, Aizawl
Functions exposed
The visible panel appears to include administrative functions such as:
Complaint/Suggestion Notices Accounts Training Circulars/Office Orders Banner management Other CMS functions
This suggests the interface may be part of a content/administrative management system, rather than necessarily being the central CAG infrastructure.
That distinction should be investigated.
{inline(s["title"])}
CAG's public material also shows that cybersecurity is an established concern within the organisation.
A CAG circular regarding NIC access instructs officials to use KAVACH for two-factor authentication for NIC-hosted email and applications, and references reporting cyber incidents to CERT-In within the applicable reporting window. Comptroller and Auditor General of India
CAG subsite pages also publicly provide links for:
Cyber Security Guidelines Data and Network Security Cyber incident reporting KAVACH security-related SOPs Comptroller and Auditor General of India
This is useful context for the report because it shows that the organisation has documented cybersecurity procedures; it does not establish whether those controls were involved or bypassed in this incident.
{inline(s["title"])}
At this stage, these should be classified as potential techniques requiring forensic validation.
TechniqueIDRelevanceExploit Public-Facing ApplicationT1190Possible initial accessValid AccountsT1078Possible if admin credentials were compromisedExternal Remote ServicesT1133Possible depending on access mechanismServer Software Component: Web ShellT1505.003Relevant if web shell is genuineData from Local SystemT1005Possible if database/server data was collectedAutomated CollectionT1119Possible if bulk database extraction occurredExfiltration Over Web ServiceT1567Possible if stolen data was transferred externallyAccount ManipulationT1098Possible if administrative accounts were created/modified
None of these should currently be presented as confirmed attacker techniques.
{inline(s["title"])}
IndicatorValueStatusTarget domaincag.gov.inConfirmed target in listingListing discovery2026-10-02 02:24:05 UTCScreenshot evidenceClaimed price$300Threat-actor claimClaimed databaseYesUnverifiedClaimed admin panelYesScreenshot-supported claimClaimed web shellYesUnverifiedAlleged attacker handle0x4zir / similarScreenshot-derived; preserve exact original evidenceProof screenshotHosted under CAG domain, according to listingRequires independent validationAdmin URL/admin visible in screenshotScreenshot-derivedCAG websitecag.gov.inOfficial domain
I would not publish the attacker's Telegram contact information in your public CyberRakshakLabs article.
{inline(s["title"])}
FindingConfidenceDark-web listing existsHigh — supplied screenshotListing targets CAGHighListing appeared on 2 Oct 2026HighActor claims database accessHigh — claim onlyActor claims web-shell accessHigh — claim onlyScreenshot shows CAG-related admin interfaceMedium–HighSuccessful admin compromiseMedium / requires validationActual database exfiltrationLow / unverifiedWeb shell actually installedLow / unverifiedRoot causeUnknownAttacker identityUnknownData publicly leakedNot establishedFull CAG infrastructure compromisedNot established
{inline(s["title"])}
If this claim has not already been investigated, the highest-value forensic checks are:
Web server
Check:
access logs error logs PHP logs WAF logs reverse-proxy logs file creation timestamps recently modified PHP files uploaded files
Especially:
*.php *.phtml *.php5 *.phar
and unexpected files under:
/uploads/ /webroot/ /admin/ CMS
Review:
admin login logs failed login attempts session creation password resets new administrator accounts privilege changes plugin/module changes CMS configuration changes
Database
Check:
new users privilege changes suspicious SQL queries bulk SELECT activity database exports unexpected tables modified application configuration credential changes
Web shell hunting
Search for:
eval( base64_decode( gzinflate( gzdecode( shell_exec( system( passthru( proc_open( popen( assert( This is not sufficient by itself because legitimate applications may contain some of these functions; the investigation should correlate file location, timestamps, code structure and execution logs.
Network
Review:
outbound connections from web servers unusual destinations large outbound transfers database connections command-and-control indicators DNS anomalies
{inline(s["title"])}
The most important question isn't:
“Did someone hack cag.gov.in?”
It is:
“How did the attacker move from the public-facing application to the administrative interface, and did that access reach the database or server operating system?”
That gives investigators a much more useful chain:
{inline(s["title"])}
Current conclusion This is a credible threat-intelligence lead that warrants immediate validation, but it should not yet be labelled publicly as a confirmed CAG data breach.
The most interesting element is the apparent combination of:
Website + Admin Panel + Web Shell + Database
If independently validated, this would represent a significantly more serious compromise than ordinary website defacement.
However, the current evidence primarily consists of a threat-actor marketplace claim and screenshots.
The official CAG website is currently accessible and serving normal content, while CAG's own documentation confirms that its web environment historically involved a large multi-subsite CMS architecture and that an earlier documented stack was considered outdated. Comptroller and Auditor General of India
Therefore:
Observation ≠ Validation ≠ Attribution
And:
A screenshot showing access is evidence of a claim — not automatically proof of the full compromise scope. Recommended CyberRakshakLabs headline CAG.gov.in Under Alleged Attack: Database, Admin Panel and Web Shell Offered for $300
Subtitle:
A newly observed dark-web listing claims compromise of India's Comptroller and Auditor General website. Screenshots suggest access to a CAG administrative interface, but database theft and web-shell access remain independently unverified. This is the framing I recommend for your CyberRakshakLabs Research Library because it is technically interesting without overstating an unconfirmed breach.
Key takeaway:
🔴 The listing is real. The compromise claim requires validation.
🎥 CyberRakshakLabs: https://cyberrakshaklabs.in/#research
💬 WhatsApp: https://whatsapp.com/channel/0029VaWsO0J1CYobJ9R6Ot0u
💼 LinkedIn: https://www.linkedin.com/company/135288406/admin/page-posts/published/
▶️ YouTube: https://youtube.com/@cyberrakshaklabs
📸 Instagram: https://www.instagram.com/vi.vekkumar1695/
𝕏 (Twitter): https://x.com/vivekkumar86538/
📘 Facebook: https://www.facebook.com/VK.CEH