Breach tracker

Breach report

GMDC tells exchanges CERT-In flagged a probable data breach linked to its website

ConfirmedDisclosed Report published IndiaOtherBy Vivek Kumar
Records UnknownCause Unknown

Gujarat Mineral Development Corporation said on 4 September that CERT-In had warned it of a probable data breach linked to gmdcltd.com. It started an investigation and says core systems kept working.

What happened

Gujarat Mineral Development Corporation (GMDC), a Government of Gujarat mining company listed on the NSE and BSE, made a Regulation 30 disclosure to both exchanges on 4 September 2026. It said it had received an intimation from CERT-In, India's national cyber security agency, that there may be a probable data breach relating to the company at its website, gmdcltd.com.

GMDC said it immediately activated its verification process and its cyber security incident response and investigation mechanism. It has engaged internal and external cyber security experts to assess the nature, scope and impact of the probable breach, based on the CERT-In advisory.

What was exposed

The filing does not say what data may be involved, how many people could be affected or how the breach happened. The CERT-In notice relates to the company's website. GMDC has not said what information was held there, or whether personal data of vendors, bidders, staff, job applicants or shareholders is involved.

Confirmed vs. claimed

Confirmed by GMDC (exchange filing, 4 Sep 2026): CERT-In told the company of a probable data breach linked to its website; GMDC started its incident response; internal and external experts are assessing it; core operations and systems remained fully functional.

Not confirmed: that data was actually taken, what kind of data, and how much. GMDC itself calls it a probable breach. Its later exchange filings, up to 8 October 2026, contain no update on the investigation, and we found no claim by a hacking group naming GMDC this year.

What to do if you are affected

  • If you have dealt with GMDC as a vendor, bidder or job applicant, be careful with emails or calls that use GMDC's name to ask for fees, bank details or documents. Check them against the official contacts on the company's website before acting.
  • If you created an account on any GMDC web portal, change that password, and any other account where you used the same one.
  • Shareholders do not need to do anything because of this filing; watch for further disclosures from the company.
  • If you are defrauded, call 1930 or report at cybercrime.gov.in.

Sources

More breaches in India