Breach report
GMDC tells exchanges CERT-In flagged a probable data breach linked to its website
Gujarat Mineral Development Corporation said on 4 September that CERT-In had warned it of a probable data breach linked to gmdcltd.com. It started an investigation and says core systems kept working.
What happened
Gujarat Mineral Development Corporation (GMDC), a Government of Gujarat mining company listed on the NSE and BSE, made a Regulation 30 disclosure to both exchanges on 4 September 2026. It said it had received an intimation from CERT-In, India's national cyber security agency, that there may be a probable data breach relating to the company at its website, gmdcltd.com.
GMDC said it immediately activated its verification process and its cyber security incident response and investigation mechanism. It has engaged internal and external cyber security experts to assess the nature, scope and impact of the probable breach, based on the CERT-In advisory.
What was exposed
The filing does not say what data may be involved, how many people could be affected or how the breach happened. The CERT-In notice relates to the company's website. GMDC has not said what information was held there, or whether personal data of vendors, bidders, staff, job applicants or shareholders is involved.
Confirmed vs. claimed
Confirmed by GMDC (exchange filing, 4 Sep 2026): CERT-In told the company of a probable data breach linked to its website; GMDC started its incident response; internal and external experts are assessing it; core operations and systems remained fully functional.
Not confirmed: that data was actually taken, what kind of data, and how much. GMDC itself calls it a probable breach. Its later exchange filings, up to 8 October 2026, contain no update on the investigation, and we found no claim by a hacking group naming GMDC this year.
What to do if you are affected
- If you have dealt with GMDC as a vendor, bidder or job applicant, be careful with emails or calls that use GMDC's name to ask for fees, bank details or documents. Check them against the official contacts on the company's website before acting.
- If you created an account on any GMDC web portal, change that password, and any other account where you used the same one.
- Shareholders do not need to do anything because of this filing; watch for further disclosures from the company.
- If you are defrauded, call 1930 or report at cybercrime.gov.in.
Sources
- GMDC — Intimation of probable data breach incident, Regulation 30 filing on NSE (4 Sep 2026) Primary
- GMDC — Same filing on BSE (4 Sep 2026) Primary
- PSU Connect — GMDC informs stock exchanges of probable data breach incident (4 Sep 2026) Secondary
- Kalkine — GMDC: what does the probable data breach intimation mean (4 Sep 2026) Secondary
More breaches in India
- RapiPay Fintech — 07 Oct 2026
- West Bengal State Data Centre — 22 Sep 2026
- Cars24 — 04 Sep 2026
- Bajaj Life Insurance — 25 Aug 2026
- Vimta Labs — 21 Aug 2026