CYBERRAKSHAK LABS Β· RESEARCH #044

🚨 ICMR Data Exposure Claim Emerges Again: Threat Actor Advertises 21 GB Database for $1,200

A newly observed dark-web listing claims to offer an ICMR database β€” but the key intelligence question is whether the advertised data is genuine, fresh and attributable to ICMR.

By Vivek Kumar Β· Published 28 September 2026
RESEARCH#044
CATEGORYThreat Intelligence / Dark Web / Data Exposure
CRL ASSESSMENTHIGH
RESEARCH LEVELDeep Research
PUBLISHED2026-09-28
Source & social links: LinkedIn Post β†— WhatsApp β†—YouTube β†—
How CyberRakshakLabs researches threats β†’
The listing is new. The breach is not yet confirmed. The supplied CyberRakshakLabs research examines a dark-web listing dated 27 September 2026 that claims to offer a 21 GB database allegedly belonging to the Indian Council of Medical Research (ICMR) for $1,200. The central intelligence question is not simply whether the listing exists, but whether the advertised data is genuine, fresh and actually sourced from ICMR.
21 GBAlleged database size in the observed listing.
$1,200Asking price stated by the seller.
UNVERIFIEDNo public evidence in the supplied source confirms a new ICMR compromise.
Executive Summary

A newly observed dark-web listing dated 27 September 2026 claims to offer a 21 GB database allegedly belonging to Indian Council of Medical Research (ICMR) and references icmr.gov.in. The listing advertises Telegram contact and an asking price of $1,200.

The supplied research explicitly does not treat the listing as proof of a new ICMR breach. There is currently no independent public evidence in the supplied material confirming that the advertised dataset is genuine, newly obtained from ICMR, or the result of a new compromise of ICMR infrastructure.

CyberRakshakLabs assessment: Threat Intelligence Lead / Dark-Web Exposure Claim β€” unverified.
What Was Observed?
Alleged victim: Indian Council of Medical Research (ICMR)
Referenced domain: icmr.gov.in
Alleged dataset size: 21 GB
Asking price: $1,200
Contact method: Telegram
Discovery timestamp: 2026-09-27 01:26:02 UTC
Authenticity: Unverified
New compromise confirmed: No

The supplied screenshot is therefore an important intelligence artifact, but it is not by itself proof that the advertised database exists or originated from ICMR.

Listing β‰  Breach

A threat actor can advertise genuine newly stolen data, previously leaked data, a subset of an older dataset, information obtained from another organisation, aggregated records, fabricated samples, or a completely fraudulent listing designed to collect money or establish credibility.

LISTING
↓
CLAIM
↓
VALIDATION
↓
PROVENANCE
↓
ATTRIBUTION

That is why the supplied research keeps two distinctions at the centre of the analysis:

Listing β‰  Breach
Claim β‰  Attribution
Why the 2026 Claim Is Significant

The supplied research places the new listing beside the history of an earlier ICMR-related data-exposure investigation. It states that in October 2023, reporting emerged that approximately 81.5 crore Indian records containing sensitive personal information were being offered on the dark web.

The reported historical material included names, phone numbers, addresses and Aadhaar/passport-related information. The source says samples were reportedly examined and matched relevant data, four people were subsequently arrested in connection with the investigation, and later reporting stated that the ICMR investigation had been taken up by the CBI.

That history makes the 2026 listing important to investigate, but the supplied article explicitly states that there is no public evidence establishing a connection between the new listing and the 2023 incident.

2023 vs 2026 β€” Why We Must Not Automatically Connect Them
2023: approximately 81.5 crore records were reported in the earlier exposure; samples were reportedly validated and law-enforcement investigation followed.
2026: a newly observed listing claims a 21 GB ICMR database is available for $1,200; the dataset itself has not been independently validated in the supplied material.
Threat actor: β€œpwn0001” was reported in the 2023 context, but no attacker identity is established for the 2026 listing.
New compromise: unconfirmed.

The differences in reported scale, pricing and listing context make provenance analysis more important than assuming continuity.

Three Possible Explanations

Scenario 1 β€” New Data Compromise

Attacker Access β†’ ICMR System / Database β†’ Data Extraction β†’ 21 GB Dataset β†’ Dark-Web Sale

This is the most serious possibility, but the supplied research says there is currently insufficient public evidence to confirm this chain.

Scenario 2 β€” Previously Exposed Data

Old Breach β†’ Data Aggregation β†’ Filtering / Restructuring β†’ 21 GB Archive β†’ New Listing

The listing could therefore be new even if the underlying data is not.

Scenario 3 β€” Fraudulent Dark-Web Listing

A seller could claim β€œICMR database β€” 21 GB” without possessing genuine ICMR data. The supplied research therefore treats the listing itself as an intelligence lead that requires investigation.

How Can the Dataset Be Proven?

The supplied research proposes a provenance-first validation process:

A β€” Does the dataset actually exist?
Obtain a legally authorised sample through appropriate investigative channels.
B β€” Does it correspond to ICMR?
Examine database schema, table names, field structures, application-specific identifiers, timestamps, metadata and known data models.
C β€” Is it fresh?
Compare timestamps and records against known historical datasets.
D β€” Is it duplicated?
Fingerprint samples and compare them against previously exposed datasets where legally and ethically possible.
E β€” Does it contain unique information?
Recently generated records or unique fields can help establish freshness.
F β€” Can records be independently validated?
Use authorised verification rather than exposing affected individuals.
The 21 GB Problem: File Size Is Not Provenance

The supplied research makes an important point: 21 GB alone tells investigators very little.

The archive could contain database dumps, CSV/JSON files, logs, attachments, duplicated records, images, compressed archives, application backups or older datasets.

File size is not evidence of breach severity.

The useful questions are:

How many unique records?
What data categories?
What date range?
What source system?
What proportion is duplicated?
What evidence proves provenance?
Potential Sensitivity β€” Without Claiming What the Dataset Contains

The supplied research explicitly frames this as a risk assessment, not a claim about the contents of the 21 GB dataset.

Depending on provenance, healthcare-related information could potentially include personal identifiers, contact information, demographic information, healthcare-related records, laboratory information, research information, administrative records or internal organisational information.

Identity + Health Context = High-Value Social Engineering Material

If such information were genuine and exposed, the downstream risk could include highly personalised social engineering. But the supplied source does not establish that these categories are present in the advertised dataset.

How Exposed Data Can Be Weaponised

The supplied research describes the potential downstream chain:

DATA β†’ PROFILING β†’ TARGET SELECTION β†’ SOCIAL ENGINEERING β†’ IMPERSONATION β†’ FINANCIAL FRAUD

For example, healthcare context could potentially be used to make a fraudulent verification or documentation message appear credible. The attacker does not necessarily need to compromise a victim's bank first if exposed information can be used to manufacture trust.

The ICMR Digital Ecosystem Is Larger Than the Main Website

The supplied research notes that ICMR-associated public infrastructure includes multiple digital portals, including a Data Repository Portal, surveillance-related systems and research infrastructure.

This illustrates a broader security principle: the protection boundary is not only the public website.

Website β†’ Application β†’ API β†’ Authentication β†’ Database β†’ Researcher β†’ Vendor β†’ Cloud β†’ Backup β†’ Export β†’ Archive

Every connection can become part of the data-security lifecycle.

Potential Attack Paths β€” Investigation Hypotheses Only

Because the current listing has not been technically validated, the supplied research does not claim one specific attack vector. It proposes areas investigators should examine:

Internet-facing application: authentication weakness, exposed API, vulnerable application, misconfiguration or identity compromise.
Identity: stolen credentials, compromised privileged accounts, session/token abuse or MFA weaknesses.
Database: exposed database, excessive permissions, unauthorised export or compromised application account.
Third-party access: vendor compromise, researcher account compromise, data-processing partner or cloud/service provider.
Insider / authorised-access abuse: excessive privileges, bulk export, unauthorised copying or credential sharing.

These are investigation hypotheses only, not findings about the current ICMR claim.

MITRE ATT&CK Investigation Mapping

The supplied article maps potential investigation areas to MITRE ATT&CK techniques, while explicitly warning that these are not confirmed ICMR TTPs.

Valid Accounts β€” T1078
External Remote Services β€” T1133
Data from Information Repositories β€” T1213
Data from Local System β€” T1005
Automated Collection β€” T1119
Archive Collected Data β€” T1560
Exfiltration Over Web Service β€” T1567
Exfiltration Over C2 Channel β€” T1041
Phishing β€” T1566
Account Manipulation β€” T1098
SOC Hunting Recommendations

If an organisation is investigating this claim, the supplied research recommends prioritising:

Identity: unusual privileged logins, impossible travel, new MFA devices, new service accounts, unusual API authentication and dormant account activity.
Database: bulk SELECT operations, unusual database exports, large query volumes, privileged database activity, new database users and unusual access times.
Network: abnormal outbound transfers, new external destinations, large compressed archives, unusual cloud-storage uploads and unexpected database connections.
Endpoint: archive creation, credential dumping, database-client execution, PowerShell/cmd anomalies and suspicious administrative tools.
Application/API: abnormal API requests, excessive record enumeration, authentication failures followed by successful access, unusual API tokens and endpoint enumeration.
What Should Be Done Now?
1. Preserve evidence β€” listing timestamp, screenshots, seller identity, listing text, claimed file size, price, associated identifiers and legally obtained cryptographic hashes.
2. Establish dataset provenance β€” determine whether records correspond to current systems, historical systems, third-party datasets or previously leaked datasets.
3. Perform retrospective hunting β€” review logs around the period corresponding to the earliest confirmed appearance of the dataset.
4. Review privileged accounts β€” database administrators, API accounts, service accounts, researchers, vendors and cloud administrators.
5. Hunt for bulk extraction β€” investigate large-volume database reads, exports and outbound transfers.
6. Rotate potentially exposed credentials β€” after evidence collection and according to the incident-response plan.
7. Review third-party access β€” a compromise may originate outside primary infrastructure.
Evidence Classification
High confidence: a new listing claiming an ICMR 21 GB database exists, based on the supplied screenshot.
High confidence: the listing was observed on 27 September 2026 based on the screenshot timestamp.
High confidence: the seller claims the database belongs to ICMR.
Unverified: the database actually contains ICMR data.
Unverified: the database was stolen in a new 2026 breach.
Unverified: ICMR infrastructure was compromised.
Unverified: the 21 GB represents newly stolen data.
Unverified: connection to the 2023 ICMR incident.
Unknown: exact attack vector and attacker identity.

This evidence classification is central to treating the item as threat intelligence rather than a confirmed breach announcement.

CyberRakshakLabs Assessment: THREAT INTELLIGENCE LEAD β€” UNVERIFIED DATA-EXPOSURE CLAIM. The supplied research recommends calling it β€œan alleged ICMR data exposure claim observed on the dark web” rather than a confirmed ICMR breach.
OBSERVE β†’ VALIDATE β†’ CORRELATE β†’ ATTRIBUTE β†’ RESPOND

πŸ”₯ Final CyberRakshakLabs Takeaway

The new ICMR listing is a warningβ€”but the warning is not yet proof of a new breach.

The 2023 ICMR incident demonstrates the potential scale and sensitivity of Indian health-related data exposure, while the new 2026 listing raises a fresh question: is there another compromise, or are threat actors recycling previously exposed information?

Until the dataset is independently validated, that question remains open.

The listing is new. The breach is not yet confirmed. The investigation should start with provenance.

CyberRakshakLabs Think Before You Click. Stay Aware. Stay Secure.