Press Trust of India (PTI) Listed by lockbit Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The Press Trust of India (PTI) Listed by lockbit Ransomware Group (reported October 21, 2020) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
What happened
Press Trust of India was added to the LockBit leak site on 21 October 2020. The group asserted that it had exfiltrated internal files during a ransomware intrusion. No independent confirmation of the claim has been published, and the organisation has not released a statement detailing the scope or timing of any intrusion. The number of people potentially affected is recorded as unknown.
Inside lockbit
LockBit operates as a ransomware-as-a-service group that supplies encryption tools to affiliate attackers in exchange for a share of ransom payments. Its standard approach includes encrypting systems and, when data are copied beforehand, publishing samples or file listings on a dedicated leak site to pressure victims. The group has appeared in multiple public reports since 2019 and has been linked to intrusions across corporate, government and media sectors. Any specific assertion about Press Trust of India originates solely from the group’s own site listing and has not been verified by third parties.
Press Trust of India (PTI) and its sector
Press Trust of India is India’s primary wire service, supplying news copy, photographs and video to domestic and international outlets. In the course of its work the agency routinely receives and stores reporting material, internal editorial communications, contributor details and administrative records. A breach at such an organisation can affect not only staff but also sources, freelancers and partner media entities whose information appears in operational files.
The information in question
The only detail released is that internal files were claimed to have been taken. No inventory of file types, no count of records and no indication of whether personal data of third parties were present have been made public. Organisations of this kind commonly hold contact information for journalists and sources, internal email archives and contractual documents, yet the exact composition of any exfiltrated material in this case remains unconfirmed.
What's at stake
For individuals named in internal files the main risks are secondary: their contact details or professional relationships could be used in targeted social-engineering attempts. For the agency itself, exposure of unpublished reporting material or source lists can erode trust with contributors and complicate ongoing work. Because the scale of the data and any subsequent distribution are unknown, the concrete consequences cannot yet be measured.
If your data was in this claimed breach
Monitor email accounts and professional contacts for unusual messages that reference PTI-related work. Enable multi-factor authentication on any services that may share login details with the agency. Individuals can also run a free exposure scan of their email address against known breach datasets to check whether their information has appeared in other incidents.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Accenture Listed by lockbit Ransomware GroupKopter Listed by lockbit Ransomware GroupBangkok Airways Listed by lockbit Ransomware GroupMerseyrail (Rail network) Listed by lockbit Ransomware GroupLatest breaches
Publicly posted by lockbit — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.