Case study

Defending massive OTT data

18 February 2024 · 6 min read

A CERT advisory flagged that emails and passwords belonging to users of one of India's largest regional streaming platforms were being offered for sale on the darknet. The volume was enormous — the platform's own account put it at more than five crore records.

Codesnag was brought in by referral from trusted authorities rather than by a sales conversation. That matters more than it sounds: by the time a regulator is involved, the question has already moved from whether there was a breach to what you are going to do about it, and on what timeline.

The team ran rapid incident response against the platform's live surface, identified the weak links that had made the extraction possible, and traced the sellers behind the darknet listing. Both were done inside a week, to CERT's standards.

The lasting outcome was not the takedown. It was that the application was hardened against the same class of attack, and that the response met a regulator's bar rather than an internal one — which is the difference between an incident that closes and an incident that follows you.

Figures and timelines here are Codesnag’s own account of the engagement. Clients are not named.