A cyber threat actor known as "ShinyHunters" supposedly posted a data dump of a hack crypto exchange Buyucoin, (
https://www.buyucoin.com/) an Indian crypto exchange.
The Buyucoin archive leaked by the threat actor this week includes three different data dumps allegedly of the exchange's MongoDB database. This archive contains three tar files named after the date the database was dumped, which was on June 1st, 2020, July 14th, 2020, and September 5th, 2020.
It is unknown if the threat actor performed these dumps on those dates or if they are backups created by Buyucoin.
These database dumps contain tables for user records, cryptocurrency trade transactions, linked bank account information, and others used internally by the exchange.
The user records table contains the information for 161,487 members. It includes email addresses, country, bcrypt hashed passwords, mobile numbers, and Google sign-in tokens if used when registering an account at the site.
https://www.bleepingcomputer.com/news/security/data-breach-at-buyucoin-crypto-exchange-leaks-user-info-trades/So I would advise our Indian crypto enthusiast, if they have an account on that exchange, it is better to update your password just to be sure. Also, there could be incoming phishing emails once this data reaches another groups so be very careful as well.