-
A hacker using the name 0x4ziz claims to have broken into India’s CAG website and is selling access for $300.
-
The alleged package includes database access, an admin panel, and a web shell, but none of this is confirmed yet.
-
A fresh report from CyberRakshakLabs found possible signs of an admin panel breach, while the bigger claims remain unverified.
A threat actor has come forward with a bold claim. The hacker, using the alias 0x4ziz, says they broke into the official website of India’s Comptroller and Auditor General (CAG). The CAG is the government body that audits India’s public spending.
According to a post flagged by the cybersecurity account CyberPulse, the actor found and used a weak spot on the site, cag.gov.in. They are now offering what they call full access for just $300.
This story is still developing. No government agency has confirmed a breach happened. But the claim is serious enough that it deserves a close look, piece by piece.
What the Hacker is Selling
CyberPulse reported that 0x4ziz listed three things for sale. The first is database access. The second is control of an admin panel. The third is a web shell, a tool that lets someone run commands on a hacked server from far away.
The hacker also shared a picture. The image was meant to work as proof that the break-in really happened. However, CyberPulse was careful to note that none of these claims had been checked by outside experts. The post should still be treated as unverified for now.
This kind of listing is common on hacker forums. Sellers often post small samples or screenshots to build trust with buyers. That does not mean the claim is true. It only means the seller wants it to look true.
Right now, there is no public evidence showing that CAG’s actual records were taken. There is also no proof that a working web shell sits on CAG’s servers today. Until a trusted source checks the data firsthand, the claim remains just that, a claim.
New Research Adds a Small but Important Clue
A cybersecurity research group called CyberRakshakLabs looked into this same case. Their report came out on October 2, 2026. It focused on the exact claim tied to cag.gov.in.
The researchers found something worth noting. Their write-up points to apparent evidence connected to an admin panel. This means there might be some real sign that a hacker reached a part of the website meant only for staff. That said, the report draws a clear line. It states that the claims about stolen database records and a working web shell are still unverified.
This matters because it shows a careful, step-by-step approach to the story. One part of the claim has a small amount of supporting evidence. The other two parts do not, at least not yet. Readers should hold onto that difference. Not every part of a hacking claim carries the same weight.
Security researchers often work this way. They check each piece of a claim on its own. They do not treat a whole story as true or false all at once. This keeps reporting accurate and fair to everyone involved, including the organization that may have been targeted.
CAG’s Website is Still Online and Working
As of now, the official CAG website remains live and reachable. Visitors can still open cag.gov.in and browse its pages like normal. The site continues to post fresh material too. Reports dated September 28 and August 12, 2026 are listed on its notice page, well after the alleged break-in would have happened.
A working website does not rule out a hack, though. Other government systems have also suffered confirmed data exposures, including a breach at the UK Department for Education that exposed 607,000 records.
A hacker can slip into a hidden part of a system, like an admin tool or a database, without ever taking the public site offline. Think of it like a thief sneaking into a storeroom while the front shop stays open for customers. Shoppers outside would never notice a thing.
A separate technology scan of the CAG site, carried out by Web Tech Survey, lists several tools running behind the site in 2026. These include Apache, Microsoft SharePoint, and jQuery, among others. Finding these tools on a scan does not prove any of them caused the alleged break-in. It simply shows what technology powers the site.
Right now, nobody outside the hacker and the two research groups has confirmed what truly happened. The identity of 0x4ziz is still unknown. They have not publicly named the exact weak spot they claim to have exploited. Whether anyone copied and removed real CAG data remains unclear.
This report does not include any login details, hacking code, or private links tied to the claim. Sharing that kind of material would only help bad actors, not readers.
For now, the safest way to describe this story is simple. A hacker claims to have broken into a major Indian government website and wants money for the access. One part of that claim has a small clue backing it. The rest do not. Until CAG itself, India’s cybersecurity authorities, or independent technical teams step in to confirm or deny the claim, it stays exactly that: a claim.
Readers should treat any news about CAG’s systems with care until an official statement arrives. Breach claims move fast online, but facts take longer to confirm.