The RailOne mobile application has emerged as the primary digital platform for railway passengers, crossing 4.55 crore downloads since its launch while Indian Railways has simultaneously intensified cyber security and anti-fraud measures to protect its online ticketing ecosystem.
According to information shared by Union Minister for Railways and Electronics & Information Technology Ashwini Vaishnaw in a written reply in the Lok Sabha on Wednesday, the RailOne app has recorded average daily bookings of 9.65 lakh tickets, comprising approximately 2.75 lakh reserved tickets and 6.89 lakh unreserved tickets.
Launched on July 1, 2025, the RailOne application integrates all major passenger-facing services of Indian Railways into a single platform. Besides reserved and unreserved ticket booking, the app offers platform ticket booking, train enquiries, PNR status, RailMadad services and several other passenger facilities, enabling users to access the Passenger Reservation System through their mobile phones.
The Minister said the RailMadad grievance redressal platform has also played a significant role in improving passenger services. During 2025-26, RailMadad provided assistance in 6,94,368 cases and received 89.49 per cent excellent and satisfactory feedback from users. The platform enables passengers to lodge complaints or seek assistance through multiple channels, including the RailMadad website and app, the 139 helpline and SMS services. Complaint handling is supported by an automated assignment and escalation mechanism to ensure timely resolution.
Indian Railways has maintained a consistently high grievance disposal rate over the past three years, resolving 99.98 per cent of complaints in 2023-24, 99.99 per cent in 2024-25 and 99.98 per cent in 2025-26.
The Minister also highlighted a series of cyber security measures introduced to safeguard the railway reservation system against fraud and cyber attacks, particularly during high-demand Tatkal bookings.
Among the key initiatives is mandatory Aadhaar authentication for booking Tatkal tickets online. The measure is intended to curb the creation of fake or multiple user accounts operated by unauthorised agents and improve transparency in ticket allocation. Aadhaar-based One-Time Password (OTP) verification has also been introduced for online Tatkal bookings on selected trains.
Indian Railways has strengthened application-level security by deploying multiple safeguards against scripting, brute-force attacks and Distributed Denial of Service (DDoS) attacks, while network infrastructure has been upgraded with advanced firewalls, intrusion prevention systems, application delivery controllers and web application firewalls.
The reservation system is protected through multiple internet service providers with an aggregated DDoS mitigation capacity of nearly 30 Gbps. Enterprise-grade Content Delivery Network (CDN), anti-bot technology, secure Domain Name System (DNS) and Web Application Firewall services have also been deployed to enhance performance and mitigate cyber threats. In addition, specialised agencies have been engaged for deep and dark web monitoring, digital risk protection and incident response.
The reservation system is hosted at a dedicated ISO 27001-certified data centre in Chanakyapuri, New Delhi, with restricted physical access and CCTV surveillance. Security monitoring is carried out round the clock through integration with the Indian Computer Emergency Response Team’s Threat and Situational Awareness Projects (CERT-In TSAP), while internet traffic is continuously monitored by CERT-In and the National Critical Information Infrastructure Protection Centre (NCIIPC).
To curb fraudulent activities, Indian Railways has undertaken extensive verification of user accounts. Between January 1, 2024 and June 30, 2026, more than 6.68 crore user accounts were deactivated and over 6.22 crore accounts were placed under temporary suspension pending revalidation. The government clarified that no accounts were deactivated for failure to link Aadhaar. Suspicious accounts were identified based on parameters such as unusual mobile numbers, email domains and IP addresses.
During 2025-26 and the first quarter of 2026-27, Indian Railways lodged 530 complaints related to suspicious ticket bookings on the National Cyber Crime Portal and blocked 13,343 suspicious email domains.
The Railways also reported significant success in blocking automated booking attempts. During the first six months of 2026, an average of 57.74 per cent of all requests received by the e-ticketing system were identified as bot-generated and blocked. In June 2026 alone, the system received 19.12 billion requests, of which 12.61 billion, or 65.95 per cent, were identified as bot traffic.
Anti-bot technology has helped mitigate malicious booking attempts by an average of 64 per cent, reducing the load on the Next Generation e-Ticketing (NGeT) system and improving the booking experience for genuine users.
The Railway Protection Force (RPF) has also continued action against illegal ticketing. Over the last five years, from 2021 to June 2026, as many as 22,676 touts were arrested and legal action initiated under the provisions of the Railways Act, 1989.
The Ministry of Railways also shared data highlighting the growing preference for digital ticket booking. Between June 2025 and June 2026, Indian Railways booked a total of 65.08 crore reserved tickets. Of these, 57.90 crore tickets, accounting for 89 per cent of all bookings, were booked online, while 7.18 crore tickets, or 11 per cent, were purchased through reservation counters.
According to the Ministry, the combined expansion of digital passenger services through the RailOne platform and strengthened cyber security measures has improved passenger convenience while ensuring a more secure, transparent and reliable online ticketing system.




