Menu

Cyberattack or insider leak? Kochi Metro data breach under police scanner in Keralam

Police cyber experts are expected to examine the affected computer, printer, email trails and other digital systems to establish how the documents were accessed and transmitted.

Published Sep 14, 2026 | 1:11 PMUpdated Sep 14, 2026 | 1:11 PM

Kochi metro.
Make Us Your Preferred Source on Google

The Kochi City Police have launched a detailed probe into the alleged leakage of confidential information from the Kochi Metro Rail Ltd (KMRL) corporate office, with investigators examining whether the incident was caused by a cyberattack or involved an insider deliberately passing on data.

The investigation followed a complaint from KMRL after confidential official documents, employees’ personal information and financial transaction details were found circulating in WhatsApp groups.

According to the complaint, a computer used by the IT section at KMRL’s corporate office on the fourth floor of the Jawaharlal Nehru Stadium Metro station complex was allegedly compromised. A printer connected to the system and used for official work was also reportedly accessed.

The leaked material surfaced in a WhatsApp group associated with the Unified Kochi Metro Rail Reform and Development Forum, a group involved in discussions on the development of the metro system. Police are expected to question members who circulated the documents and trace how the material reached the group.

Ernakulam District Collector and KMRL Managing Director G Priyanka confirmed that important documents had been leaked from the organisation. She said a substantial portion of the material was confidential and that the exact nature and extent of the breach could be established only through a detailed investigation.

The Collector said the probe was initiated after several officials raised complaints about documents being sent for photocopying and subsequently being forwarded to an external email address. Investigators are now examining whether the diversion of the documents was the result of a technical compromise or deliberate action by someone within the organisation.

Police cyber experts are expected to examine the affected computer, printer, email trails and other digital systems to establish how the documents were accessed and transmitted. The investigation will also look into the possibility of employee involvement.

Incident being treated seriously

It has not been established so far whether any sensitive operational information relating to the metro’s Central Control Room, signalling systems or station surveillance network was compromised. Police sources have indicated that no strategic or critical operational documents have been identified among the leaked material so far.

However, officials are treating the incident seriously given the nature of the information involved. KMRL has raised concerns over the possible compromise of organisational security and the privacy of its employees.

The police will also seek to establish the extent to which the leaked information has been disseminated and whether it has reached persons or entities outside the original WhatsApp group.

Priyanka said the extent of the damage could be assessed only after the investigation and assured that strict action would follow if those responsible for the leak were identified.

The central question before investigators is whether KMRL’s systems were breached by an external cybercriminal or whether confidential information was deliberately passed out by an insider.

(With inputs from Dileep V Kumar.)

Also Read:

One photo, one bot, zero expertise: How AI morphing is spreading across Keralam campuses

‘Magnifica Humanitas’: What the Pope’s AI Encyclical means for India

journalist-ad