Massive data breach forces India to shift official email infrastructure

In the wake of a breach that exposed over 16 billion passwords, India strengthens state cybersecurity with Zoho and transitions to the @mail.gov.in domain.
In the wake of a breach that exposed over 16 billion passwords, India strengthens state cybersecurity with Zoho and transitions to the @mail.gov.in domain.

 


Following a massive data breach that compromised more than 16 billion passwords across various digital platforms, the Indian government has mandated that officials migrate their official email accounts to the new @mail.gov.in domain. This domain is managed by the National Informatics Centre (NIC) and powered by the Zoho Mail platform.

The move is intended to replace the legacy @nic.in domain and bolster the security of governmental communications. Zoho, a global technology company, was awarded the contract through a public tender process after demonstrating its capacity to serve all branches of government with robust privacy controls, a scalable infrastructure, and no reliance on third-party providers.

CERT-In Issues Alert.

The decision follows a June 23 alert from CERT-In, India’s national cybersecurity agency, which identified the circulation of a massive dataset on the dark web.

The compromised data includes sensitive information from services such as Apple, Google, Facebook, Telegram, GitHub, and various VPN providers, encompassing usernames, passwords, tokens, session cookies, and other metadata.

Security Recommendations.

CERT-In has advised users to update their passwords, enable multi-factor authentication, and adopt phishing-resistant login methods. Additionally, it urged organizations to implement zero-trust security models and enhance monitoring for suspicious activities.

Zoho, the technology company now overseeing the email services, secured the government contract by proving its ability to deliver high standards of privacy, a scalable infrastructure, and independence from external vendors.

Privacy as a Priority.

Through this migration to Zoho Mail, the Indian government aims to strengthen data privacy and safeguard its critical systems amid an increasingly volatile global cybersecurity landscape.

CERT-In reiterated its recommendations for users to change their passwords, activate multi-factor authentication, and utilize phishing-resistant access methods. Organizations are also encouraged to apply zero-trust frameworks and heighten vigilance against potential threats.


Share:
Hosting Web
Most Read