Home India Ministry of Railways Parliament Question: Railway Ticket Booking System...
Date: 2025-12-10 Category: Not Applicable State: Union Government Country: India

Parliament Question: Railway Ticket Booking System

Issued by Ministry of Railways · Not Applicable

Research with AI Agent Chat with Document Generate Summary Translate Helpful Share Add to Project Create Task

Executive Summary & Key Takeaways

**Executive Summary** This document presents the Ministry of Railways' response to an unstarred question regarding the security of the railway ticket booking system. The response, due on December 10, 2025, addresses concerns about cyber attacks, data breaches, and misuse of user accounts. The Ministry outlines measures taken to enhance security and prevent fraudulent activities in the railway ticket booking system. **Key Points / Main Content** * **Security Measures:** * The Indian Railways reservation system is a robust, secure IT platform with industry-standard cyber security controls. * Multiple protective layers, including firewalls and intrusion prevention systems, safeguard the system. * The system is hosted in a secure data center certified under ISO 27001 standards. * RailTel provides cyber threat intelligence services, including threat monitoring and digital risk protection. * Regular security audits are conducted by CERT-In-empanelled agencies. * Internet traffic is continuously monitored by CERT-In and NCIIPC. * **User Account Management:** * Rigorous revalidation and verification of user accounts have been implemented. * Approximately 3.02 crore suspicious user IDs have been deactivated since January 2025. * **Anti-Bot Measures:** * Anti-bot solutions like AKAMAI are deployed to filter non-genuine users. * **Tatkal Ticket Booking Security:** * Aadhaar-based OTP verification for online tatkal ticket booking has been introduced in a phased manner and is operational in 322 trains as of December 4, 2025. * Aadhaar-based OTP for tatkal bookings at reservation counters has been introduced in a phased manner and is implemented in 211 trains as of December 4, 2025. * Confirmed tatkal ticket availability time has increased in approximately 65% of the 322 trains. * Confirmed tatkal ticket availability time has increased in approximately 95% of the 96 popular trains. * **Complaint Handling:** * Complaints related to suspiciously booked PNRs have been filed on the National Cyber Crime Portal. * **Requests and Suggestions:** * Requests and suggestions are received from various stakeholders and are examined for feasibility and justification. **Impact Analysis** **Stakeholder: Passengers** * **Impact:** Passengers benefit from increased security and fairness in the ticket booking system, particularly for tatkal tickets. They are protected from cyber fraud and misuse of their personal information. * **Action Required:** Passengers must use Aadhaar-based OTP verification for tatkal bookings to enhance security. **Stakeholder: Indian Railways / IRCTC** * **Impact:** Enhanced security measures protect the integrity of the ticket booking system and the reputation of Indian Railways. * **Action Required:** Continue implementing and monitoring security measures, conducting regular audits, and responding to emerging cyber threats. **Stakeholder: Ministry of Railways** * **Impact:** Addresses concerns raised in the Lok Sabha regarding the security of the railway ticket booking system. * **Action Required:** Provide further updates on the effectiveness of implemented measures and ongoing efforts to combat cyber threats.

Key Entities Referenced

Indian Railways: The entity whose railway ticket booking system is the subject of the questions and answers. IRCTC: Indian Railway Catering and Tourism Corporation - referenced for its security protocols in online ticketing. Aadhaar: A Unique Identification Authority of India. Aadhaar verification is being used for railway ticket booking to prevent misuse. CERT-In: Indian Computer Emergency Response Team, which monitors the ticketing system for cyber attacks. National Cyber Crime Portal: A portal where complaints have been filed regarding suspiciously booked PNRs
Official Source Record View Original Source →
See Full Document Text
GOVERNMENT OF INDIA MINISTRY OF RAILWAYS LOK SABHA UNSTARRED QUESTION NO.1736 TO BE ANSWERED ON 10.12.2025 RAILWAY TICKET BOOKING SYSTEM †1736. Dr. SAMBIT PATRA : Ms. SAYANI GHOSH : Will the Minister of Railways be pleased to state: (a) whether the Government has received complaints regarding the railway ticket booking system being compromised through malware, software, third party site etc. and if so, the details thereof; (b) whether the Government has prepared any action plan to prevent cyber attacks on Railway ticket booking website by cyber criminals and if so, the details thereof? (c) whether the security system of Indian Railways’ online ticketing platform has been repeatedly breached by organised gangs for ticket bookings within seconds by bypassing IRCTC’s security protocols and if so, the details thereof; (d) the total number of passengers affected/complaints received from passengers in this regard; (e) the details of the reasons for such large-scale cyber breaches despite repeated incidents, and whether any internal audit or accountability has been fixed for such failures and if so, the details thereof; (f) whether it is true that Aadhaar-verified IDs, IRCTC user accounts, and online payment gateways are being misused in these operations, leading to potential financial fraud and data privacy violations and if so, the details thereof; ….2/--2- (g) the number of such cases identified and whether such IDs and accounts have been blacklisted; and (h) the details of action taken, including number of cases registered, arrests made, penalties imposed? ANSWER MINISTER OF RAILWAYS, INFORMATION & BROADCASTING AND ELECTRONICS & INFORMATION TECHNOLOGY (SHRI ASHWINI VAISHNAW) (a) to (h): The reservation ticket booking system of Indian Railways is a robust and highly secure IT platform equipped with industry-standard, state-of-the-art cyber security controls. Indian Railways has taken several measures to enhance performance of reservation system and availability of regular/tatkal tickets. These measures include following: 1. Rigorous revalidation and verification of user accounts have been done. About 3.02 cr suspicious user IDs have been deactivated since January 2025. 2. Anti-bot solutions such as AKAMAI are deployed to filter non-genuine users and ensure smooth booking for legitimate passengers. 3. To curb misuse and improve fairness in tatkal bookings, Aadhaar- based One-Time Password (OTP) verification for online tatkal ticket booking has been introduced in a phased manner. It is already operational in 322 trains as on 04.12.2025. Due to the above steps, the confirmed tatkal ticket availability time has increased in about 65% of the abovementioned 322 trains. ….3/--3- 4. Aadhaar-based OTP for tatkal bookings at reservation counters has also been introduced in a phased manner and it is implemented in 211 trains as on 04.12.2025. 5. As a result of these and other measures, the confirmed tatkal ticket availability time has increased in about 95% of the 96 popular trains. 6. Complaints have been filed on the National Cyber Crime Portal for suspiciously booked PNRs. 7. Use of multiple protective layers such as network firewalls, intrusion prevention systems, application delivery controllers and web application firewalls which safeguard the system against cyber threats. The system is hosted in a dedicated, access-controlled Data Centre, secured through CCTV surveillance and end-to-end encryption. The Data Centre is certified under ISO 27001 Information Security Management System (ISMS) standards. To further strengthen cyber security posture, RailTel Corporation of India Ltd. provides comprehensive cyber threat intelligence services, including take-down services, threat monitoring, deep and dark web surveillance and digital risk protection. These services offer proactive and actionable insights into emerging cyber threats and enable improved incident response. 8. Regular security audits of the reservation system are carried out by CERT-In-empanelled Information Security Audit Agencies. Moreover, internet traffic related to the ticketing system is continuously ….4/--4- monitored by CERT-In and the National Critical Information Infrastructure Protection Centre (NCIIPC) to detect and prevent cyber attacks. Further, Requests/ suggestions/ representations, both formal and informal, are received from public representatives/organizations/rail users etc. at various levels including Railway Board, Zonal Railways, Divisional Office etc. As receipt of such requests/ suggestions/representation is a continuous and dynamic process, centralized compendium of such requests is not maintained. However, these are examined and action as found feasible and justified is taken from time to time, which is an on-going process. *****

Continue your research