About the initiative
Data breaches are on the rise around the world, even more dramatically during the COVID-19 pandemic. A data breach exposes confidential, sensitive and protected information to unauthorised actors. As a result of these breaches, data of Indian users is available to any third party over the internet for nefarious use.
The key problem here, and indeed, something that is part of the raison d’etre of this initiative is the lack of transparency, which results in a near complete lack of information. In most cases, companies fail to even acknowledge these breaches.
Internet Freedom Foundation’s (IFF) initiative, PlugTheBreach, aims to cover, report and track data breaches by providing a comprehensive database of breaches in India to increase transparency and public awareness.
What happened to this project
PlugTheBreach launched in 2022 as a crowdsourced tracker and was maintained for a couple of years. Then it stopped. The last breach recorded here dated from August 2024, and for roughly two years afterwards nothing new was added — while the breaches themselves, of course, kept happening.
Part of the reason was structural. The site pulled its records from an Airtable base at build time, and when that base was retired the site could no longer be built at all. A tracker that cannot be updated is a tracker that quietly stops being true.
It was picked back up in mid-2026 by a volunteer, after a complete rewrite. The old records were recovered from the published site, the two-year gap was filled in, and the dataset now lives in the repository as a plain file that anyone can read, check or correct. There is no longer a private backend that can disappear and take the project with it.
Contributing
This is volunteer-maintained, and it is better when more people look at it. If you know of a breach that is missing, spot a record that is wrong or out of date, or want to improve the site itself, contributions are genuinely welcome — you do not need permission to start.
The project lives at github.com/InternetFreedomFoundation/plug-the-breach.
How records are classified
Whether an organisation admitted to a breach is often more revealing than the breach itself, so every record carries one of five statuses. A claim circulating on a dark-web forum is not treated as equivalent to a confirmed incident.
- Acknowledged
- The affected entity publicly confirmed the breach.
- Partly acknowledged
- The entity confirmed an incident but disputed or withheld its scope.
- Not acknowledged
- The entity has not publicly acknowledged the breach.
- Denied
- The entity publicly denied the breach.
- Unverified
- Claimed by a third party and not independently verified.
Scale figures are recorded as reported and are frequently disputed by the affected organisation. Where no figure was ever reported, the field is left blank rather than estimated. Dates are stored at the precision we can source — sometimes only a year. Nothing in this database is derived from breached data itself; every record is built from public reporting and cited.
What a useful contribution looks like
Records live in a single JSON file in the repository, so a correction or a new incident is an ordinary pull request — no CMS account and no credentials needed. Please include at least one link to published reporting, and prefer established outlets over aggregator blogs. If the only evidence is a dark-web listing, the record belongs under Unverified, and should say so.