**Executive Summary**
This document outlines the measures Indian Railways has taken to strengthen the cybersecurity of its ticket reservation system. These include deactivating suspicious user IDs, implementing anti-bot measures, introducing Aadhaar-based OTP verification, and performing regular security audits. The deactivation of suspicious user IDs started in January 2025, and Aadhaar-based OTP verification was operational in 322 trains as of 04.12.2025.
**Key Points / Main Content**
* **User Account Security:**
* 3.02 crore suspicious user IDs have been deactivated since January 2025.
* Rigorous revalidation and verification of user accounts are being done.
* **Anti-Bot Measures:**
* Anti-bot solutions, such as AKAMAI, are deployed to filter non-genuine users.
* These measures ensure smooth booking for legitimate passengers.
* **Aadhaar-Based OTP Verification:**
* Aadhaar-based OTP verification has been introduced for online Tatkal ticket booking in a phased manner.
* Operational in 322 trains as of 04.12.2025.
* Aadhaar-based OTP verification for Tatkal bookings at reservation counters has been implemented in 211 trains as of 04.12.2025.
* **Tatkal Ticket Availability:**
* Confirmed Tatkal ticket availability time has increased in about 65% of the 322 trains due to the above measures.
* Confirmed Tatkal ticket availability time has increased in about 95% of the 96 popular trains overall.
* **Cybersecurity Infrastructure:**
* Multiple protective layers are in place, including network firewalls, intrusion prevention systems, application delivery controllers, and web application firewalls.
* The system is hosted in a dedicated, access-controlled Data Centre, secured through CCTV surveillance and end-to-end encryption.
* The Data Centre is certified under ISO 27001 ISMS standards.
* RailTel Corporation of India Ltd. provides cyber threat intelligence services.
* **Security Audits and Monitoring:**
* Regular security audits are carried out by CERT-In-empanelled Information Security Audit Agencies.
* Internet traffic related to the ticketing system is continuously monitored by CERT-In and NCIIPC.
* **Complaint Handling:**
* Complaints have been filed on the National Cyber Crime Portal for suspiciously booked PNRs.
* Requests/suggestions/ representations, both formal and informal, are received from public representatives/organizations/rail users.
**Impact Analysis**
**Rail Passengers**
* **Impact:**
* Improved fairness and reduced misuse in Tatkal ticket bookings.
* Smoother booking experience due to anti-bot measures.
* Increased availability of Tatkal tickets, leading to better chances of securing a seat.
* More secure reservation system.
* **Action Required:**
* Adhere to OTP verification processes when booking Tatkal tickets.
* Report any suspicious booking activity through the appropriate channels.
**Indian Railways IT Department**
* **Impact:**
* Enhanced cybersecurity posture of the ticket reservation system.
* Improved performance and availability of regular/Tatkal tickets.
* Strengthened protection against cyber threats.
* **Action Required:**
* Maintain and update security measures.
* Continue to monitor and audit the reservation system.
* Address complaints and suspicious activities.
**CERT-In and NCIIPC**
* **Impact:**
* Responsibility to detect and prevent cyber attacks on the Indian Railways ticketing system.
* **Action Required:**
* Conduct regular security audits of the reservation system.
* Monitor internet traffic related to the ticketing system.
Key Entities Referenced
Ministry of Railways: The ministry responsible for the Indian Railways and its policies, including the security measures for the ticket reservation system.
Indian Railways: The organization responsible for the railway network in India, taking steps to strengthen the ticket reservation system's cyber security.
Aadhaar-Based OTP Verification: A security measure implemented in Indian Railways to curb misuse in tatkal bookings, involving verification via One-Time Password linked to Aadhaar.
National Critical Information Infrastructure Protection Centre (NCIIPC): The organization that monitors internet traffic related to the ticketing system to detect and prevent cyber attacks.
CERT-In: The Indian Computer Emergency Response Team, which empanels Information Security Audit Agencies to conduct regular security audits of the reservation system and monitors internet traffic.
Ministry of Railways
Indian Railways Strengthens Ticket Reservation
System With Robust Cyber Security
3.02 Cr Suspicious User IDs Deactivated since January 2025;
Anti-Bot Measures Deployed to Ensure Genuine Ticket
Booking
Aadhaar-Based OTP Verification in 322 Trains for Online
Tatkal Ticketing and 211 Trains at Reservation Counters
Confirmed Tatkal Ticket Availability Time Increases in 95% of
the 96 Popular Trains
प्रव तथ: 11 DEC 2025 2:12PM by PIB Delhi
The reservation ticket booking system of Indian Railways is a robust and highly secure IT platform
equipped with industry-standard, state-of-the-art cyber security controls. Indian Railways has taken
several measures to enhance performance of reservation system and availability of regular/tatkal tickets.
These measures include following:
1. Rigorous revalidation and verification of user accounts have been done. About 3.02 cr suspicious user
IDs have been deactivated since January 2025.
2. Anti-bot solutions such as AKAMAI are deployed to filter non-genuine users and ensure smooth
booking for legitimate passengers.
3. To curb misuse and improve fairness in tatkal bookings, Aadhaar-based One-Time Password (OTP)
verification for online tatkal ticket booking has been introduced in a phased manner. It is already
operational in 322 trains as on 04.12.2025. Due to the above steps, the confirmed tatkal ticket availability
time has increased in about 65% of the abovementioned 322 trains.
4. Aadhaar-based OTP for tatkal bookings at reservation counters has also been introduced in a phased
manner and it is implemented in 211 trains as on 04.12.2025.
5. As a result of these and other measures, the confirmed tatkal ticket availability time has increased in
about 95% of the 96 popular trains.
6. Complaints have been filed on the National Cyber Crime Portal for suspiciously booked PNRs.
7. Use of multiple protective layers such as network firewalls, intrusion prevention systems, application
delivery controllers and web application firewalls which safeguard the system against cyber threats. The
system is hosted in a dedicated, access-controlled Data Centre, secured through CCTV surveillance andend-to-end encryption. The Data Centre is certified under ISO 27001 Information Security Management
System (ISMS) standards.
To further strengthen cyber security posture, RailTel Corporation of India Ltd. provides comprehensive
cyber threat intelligence services, including take-down services, threat monitoring, deep and dark web
surveillance and digital risk protection. These services offer proactive and actionable insights into
emerging cyber threats and enable improved incident response.
8. Regular security audits of the reservation system are carried out by CERT-In-empanelled Information
Security Audit Agencies. Moreover, internet traffic related to the ticketing system is
continuously monitored by CERT-In and the National Critical Information Infrastructure Protection Centre
(NCIIPC) to detect and prevent cyber attacks.
Further, Requests/ suggestions/ representations, both formal and informal, are received from public
representatives/organizations/rail users etc. at various levels including Railway Board, Zonal Railways,
Divisional Office etc. As receipt of such requests/ suggestions/representation is a continuous and dynamic
process, centralized compendium of such requests is not maintained. However, these are examined and
action as found feasible and justified is taken from time to time, which is an on-going process.
This information was provided by the Union Minister for Railways, Information & Broadcasting and
Electronics & Information Technology, Shri Ashwini Vaishnaw, in a written reply to a question in Lok
Sabha.
*****
Dharmendra Tewari/ Dr. Nayan Solanki/ Manik Sharma
(रलीज़ आईडी: 2202197) आगंतुक पटल : 1038
इस वज्ञ को इन भाषाओ ंम पढ़: Urdu , ही , Marathi , Bengali , Bengali-TR , Gujarati , Tamil , Telugu , Kannada