Ministry of Railways
azadi ka amrit mahotsav

RailOne App Gains Widespread Popularity Among Passengers with 4.55 Crore Downloads and Average Daily Ticket Bookings of 9.65 Lakh


Indian Railways Strengthens Anti-Fraud Measures; Over 6.68 Crore User Accounts Deactivated For Unusual Mobile Numbers, Email Domains, IP Addresses Since January 2024

530 Suspicious Booking Complaints Lodged on the National Cyber Crime Portal and 13,343 Suspicious Email Domains Blocked in the year 2025-26 & 2026-27 (till 30.06.2026)

89% of Reserved Tickets Booked Online in Indian Railways Out of 65.08 Crore Tickets Booked During June 2025–June 2026; 11% Booked Through Counters

Posted On: 22 JUL 2026 4:28PM by PIB Delhi

To improve overall passenger experience, Railways has launched RailOne App on 01.07.2025. The App can be downloaded from Android Play Store and Apple App Store.  This App enables passengers to book reserved as well as unreserved tickets on mobile phone. This App combines all the public facing services of Indian Railways like reserved ticketing, unreserved ticketing and platform ticketing, train enquiry, PNR enquiry, Railmadad, etc. into a single platform. This, in effect, brings the Passenger reservation system facility to passenger's palm. Till date more than 4.55 crore downloads of this app have been done. On an average, about, 9.65 lakh tickets are being booked on the RailOne App Daily (2.75 lakh reserved and 6.89 lakh Unreserved). The passengers can book both reserved and unreserved tickets very conveniently using this app.

RailMadad is Indian Railways grievance redressal mechanism that provides passengers an integrated platform for grievance redressal, seeking assistance and inquiry. In RailMadad, passengers can seek redressal through multiple channels such as Helpline number-139, RailMadad Web, App and SMS. RailMadad features an automated complaint assignment and auto-escalation system to ensure the timely redressal of grievances. Grievances and calls for assistance are captured in more than 30 Train and Station categories to ensure smooth journey.

In addition, during the financial year 2025–26, RailMadad provided assistance in 6,94,368 cases with 89.49% excellent and satisfactory feedback. The platform also enables passengers to share feedback on the resolution of their grievances, helping Indian Railways monitor service quality and improve passenger satisfaction. Details of grievances resolved during last three years is as under: -

Year

% of total grievances resolved

2023-2024

99.98%

2024-2025

99.99%

2025-2026

99.98%

 

The reservation ticket booking system of Indian Railways is a robust and highly secure system equipped with industry-standard, state-of-the-art cyber security controls. Indian Railways has taken the following measures to safeguard the system from cyber attacks and to prevent auto filling of forms by hacking tools for curbing frauds in tatkal ticketing booking through internet:

1. Aadhaar authentication to book tatkal  tickets –  A provision has been made to allow only Aaadhar authenticated passengers to book Tatkal tickets online. It helps in preventing the creation and operation of fake or unauthorized agent-controlled multiple user account by imposing a uniqueness constraint.  This measure acts as an effective safeguard against account multiplication and automated misuse, thereby ensuring fair allocation of tatkal tickets.  It has enhanced transparency in the online tatkal booking system.  To curb misuse and improve fairness in tatkal bookings, Aadhaar based One-Time Password (OTP) verification for online tatkal ticket booking has also been introduced on selected trains.

2. Application layer Security Control -- Several application level security controls have been implemented at multiple levels to avoid scripting, Brute-Force Attack and DDoS (Distributed Denial of Service) attacks.  A number of security measures have also been applied for handling the OWASP (Open Web Application Security Project) for application security vulnerability.

3. Network and Infrastructure Layer Security Controls – The entire ICT (Information and Communication Technology) infrastructure has been deployed on high availability mode to minimize failures.

The system is protected by industry-standard state-of-the-art and data centre grade network along with security equipment consisting of network firewalls, network intrusion prevention system, application delivery controllers and web application firewalls.

The system is also protected from volume-based DDoS (Distributed Denial of Service) attacks with ISP (Internet Service Provider) layer, DDoS Detection and Mitigation Services through multiple ISPs with aggregated DDoS mitigation capacity of nearly 30 Gbps.

The enterprise level Content Delivery Network (CDN), anti-bot, secure DNS and Web Application Firewall (WAF) services for enhanced security, better customer experience, regulating web traffic load, resource optimisation and threat mitigation have been deployed.

For comprehensive cyber threat intelligence services, specialized agencies have been engaged to undertake Deep-Dark Web Monitoring, Digital Risk Protection and improve incident response.

4. Physical Security Controls – The system is hosted in a captive data center facility Chanakyapuri, New Delhi secured with CCTV footage and restricted physical access.  The facility is ISO 27001 (Information Security Management System) certified.

5. Security Audit and Monitoring -   The system is integrated with CERT-In TSAP (Threat & Situational Awareness Projects) for round the clock monitoring of security incidents and events.

Security log monitoring of the system is being done by on-premises security team for detection and mitigation of security incidents.

6. Administrative measures – Several anti-fraud measures have been adopted to prevent unauthorized access and to ensure seamless booking for genuine users.

  • Rigorous revalidation and verification of user accounts have been done. During the period 01.01.2024 to 30.06.2026, more than 6.68 crore user accounts were deactivated and more than 6.22 crore user accounts were put under temporary suspension with option of revalidation. IRCTC has not deactivated any user account due to non-linking of Aadhaar. IRCTC adopts broad parameters for identifying suspicious user IDs on the basis of unusual mobile numbers, email domains, IP Addresses, etc.
  • Regular security audits of the reservation system are carried out by CERT-In empanelled information Security Audit Agencies.  Moreover, internet traffic related to the ticketing system is continuously monitored by CERT-In and the National Critical Information Infrastructure Protection Centre (NCIIPC) to detect and prevent cyber attacks.
  • 530 complaints have been lodged on the National Cyber Crime Portal pertaining to suspicious bookings in the year 2025-26 & 2026-27 (till 30.06.2026).
  • 13,343 suspicious email domains have been blocked in the year 2025-26 & 2026-27 (till 30.06.2026).
  • Only Aadhaar Verified Users are allowed to book Tatkal tickets and ARP (Advance Reservation Period) tickets.

 

7. Systemic Measures (Content Delivery Network and Anti BOT) -

  • To optimize system performance, Indian Railway has implemented a Content Delivery Network (CDN) to offload static content and reduce direct traffic on NGeT (Next Generation e-Ticketing) website servers.
  • In addition, anti-BOT Technology has been deployed which helps in mitigating malicious and suspicious attempts which on an average is mitigated to the extent of 64%.
  • It helps in reducing malicious traffic and providing static content reducing load on the system and thus enhancing the user experience for genuine and verified users.

 

During the last five years i.e. 2021 to 2025 and 2026 up to June, 22,676 touts have been arrested by RPF (Railway Protection Force) and legal action has been taken under the relevant provisions of the Railways Act, 1989.

The details of spurious attempts denied to access the e-ticketing system during the last six months is as under:

 

June 2026

Out of 19.12 billion requests, 12.61 billion were bots. (65.95%)

May 2026

Out of 20.07 billion requests, 12.08 billion were bots. (60.18%)

April 2026

Out of 17.33 billion requests, 10.64 billion were bots. (61.39%)

March 2026

Out of 12.44 billion requests, 05.71 billion were bots. (45.90%)

February 2026

Out of 11.01 billion requests, 05.01 billion were bots. (45.50%)

January 2026

Out of 12.35 billion requests, 07.26 billion were bots. (58.78%)

 

Average for last six months: Out of 15.38 billion requests, 8.88 billion were bots(57.74%).

The comparative data of online and counter ticket sales during the last one year (from June 2025 to June 2026) after enforcement of strict measures in online ticket booking is as under:

Online ticketing

57.90 Cr.

89%

Counter booking

07.18 Cr.

11%

Total

65.08 Cr.

100%

 

This information was provided by the Union Minister for Railways, Information & Broadcasting and Electronics & Information Technology, Shri Ashwini Vaishnaw, in a reply to questions in the Lok Sabha today.

 *****

Dharmendra Tewari/ Dr. Nayan Solanki/ Ritu Raj/ Manik Sharma


(Release ID: 2287719) Visitor Counter : 292