Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesEarnSquareMore
Thousands of records related to Indian bank transfers exposed online due to a security oversight

Thousands of records related to Indian bank transfers exposed online due to a security oversight

Bitget-RWA2025/09/26 18:12
By:Bitget-RWA

A misconfigured cloud server has resulted in the exposure of hundreds of thousands of confidential bank transfer records in India, disclosing account details, transaction amounts, and personal contact information.

Cybersecurity experts from UpGuard identified a publicly accessible Amazon cloud storage server in late August, which contained 273,000 PDF files related to bank transfers for Indian clients. 

These documents included completed transaction forms meant for processing through the National Automated Clearing House (NACH), a centralized platform used by Indian banks for handling large-scale recurring payments such as payroll, loan installments, and utility bills.

According to the researchers, the leaked data was associated with at least 38 banks and financial organizations, as reported to TechCrunch.

Although the data leak was eventually secured, the researchers stated they were unable to determine the exact origin of the breach.

After this story was published, Indian fintech firm Nupay contacted TechCrunch via email to state that it had “resolved a configuration issue in an Amazon S3 storage bucket” that held the bank transfer documents.

The reason for the data being left open to the public remains uncertain, though such security oversights are often attributed to human mistakes.

Data secured, Nupay cites ‘configuration issue’

In a blog post outlining their investigation, UpGuard’s team noted that, of a sample of 55,000 files they reviewed, over half referenced Indian lender Aye Finance, which had applied for a $171 million IPO the previous year. The State Bank of India, a government-owned institution, was the next most frequently mentioned in the sample, according to the researchers.

Upon finding the exposed information, UpGuard notified Aye Finance through its official, customer service, and grievance email contacts. The team also informed the National Payments Corporation of India (NPCI), the government agency overseeing NACH.

By early September, researchers reported that the data remained unprotected, with thousands of new files being uploaded to the exposed server each day. 

UpGuard then alerted CERT-In, India’s Computer Emergency Response Team. The data was secured soon after, according to what the researchers told TechCrunch.

Nevertheless, the party responsible for the security failure was still not identified. Representatives for Aye Finance and NCPI denied involvement in the breach, while a spokesperson for the State Bank of India acknowledged the inquiry but did not comment further.

After the article was released, Nupay admitted responsibility for the data exposure.

Neeraj Singh, Nupay’s co-founder and chief operating officer, informed TechCrunch that only “a limited set of test records with basic customer details” were stored in the Amazon S3 bucket, and asserted that “most were dummy or test files.”

The company stated that its Amazon-hosted logs “verified that there was no unauthorized access, no data leak, no misuse, and no financial consequences.”

UpGuard challenged Nupay’s statements, telling TechCrunch that only a few hundred of the thousands of files they examined appeared to be test data or included Nupay’s name. UpGuard also questioned how Nupay’s cloud logs could conclusively rule out access to the previously public Amazon S3 bucket, especially since Nupay had not requested UpGuard’s IP addresses used during their investigation.

UpGuard further pointed out that the Amazon bucket’s details were not exclusive to their team, as the public S3 bucket address had been indexed by Grayhatwarfare, a searchable database for publicly accessible cloud storage.

When TechCrunch asked, Singh from Nupay did not immediately clarify how long the Amazon S3 bucket was left open to the internet.

Originally published on September 25 and updated with additional information from Nupay.

0
0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

PoolX: Earn new token airdrops
Lock your assets and earn 10%+ APR
Lock now!

You may also like

The Rise of CFTC-Regulated Clean Energy Trading Platforms and Their Influence on the Liquidity of Renewable Assets

- CFTC's 2025 approval of CleanTrade as a SEF marked a regulatory milestone, addressing fragmentation and boosting clean energy liquidity. - Institutional clean energy investments surged to $125T by 2032, driven by ESG mandates and platforms like CleanTrade offering real-time analytics and risk tools. - Q3 2025 saw $75B in U.S. clean energy investment, highlighting growing demand for renewables despite Q2 volatility in manufacturing sectors. - CFTC's regulatory flexibility, including no-action relief for S

Bitget-RWA2025/12/14 02:46
The Rise of CFTC-Regulated Clean Energy Trading Platforms and Their Influence on the Liquidity of Renewable Assets

Zcash Halving 2025: Impact on Cryptocurrency Market Trends

- Zcash's 2025 halving reduced block rewards to 1.5625 ZEC, triggering a 950% price surge to $589 amid ZIP 1015 scarcity mechanisms. - Institutional adoption accelerated, with Grayscale acquiring 5% supply and Cypherpunk committing $100M, mirroring Bitcoin's post-halving trends. - Speculative trading drove $1.11B in Zcash futures open interest, causing 24% 24-hour price swings as retail investors chased scarcity-driven gains. - Hybrid consensus and optional privacy features differentiate Zcash from Bitcoin

Bitget-RWA2025/12/14 02:26
Zcash Halving 2025: Impact on Cryptocurrency Market Trends

ICP Network's Rapid Expansion and Increasing Institutional Embrace: Key Strategic Considerations for Long-Term Investors in Web3 Infrastructure

- ICP's 2025 growth stems from Fission/Chain Fusion upgrades enabling Bitcoin-Ethereum interoperability and Caffeine AI's no-code dApp platform attracting 2,000+ developers. - Institutional adoption surged with $1.14B TVL, Microsoft-Google partnerships, and first ICP ETP via Copper-DFINITY collaboration expanding institutional access. - Despite $4.71 price peak in November 2025, 10%+ volatility highlights risks, though 11,500 TPS capacity and $357M daily trading volume signal infrastructure strength. - Lon

Bitget-RWA2025/12/14 02:08
ICP Network's Rapid Expansion and Increasing Institutional Embrace: Key Strategic Considerations for Long-Term Investors in Web3 Infrastructure

New Prospects in STEM Learning and Career Advancement: Sustained Institutional Commitment to Academic Initiatives Fueling Tomorrow’s Innovation

- Global STEM education is accelerating as AI and engineering drive economic transformation, with 2025 government initiatives expanding AI-focused programs and workforce development. - U.S. universities report 114.4% growth in AI bachelor's enrollments, supported by corporate partnerships and $25M+ in tech industry investments for AI labs and teacher training. - EdTech's AI-powered platforms, valued at $5.3B in 2025, are projected to reach $98.1B by 2034, with startups like MagicSchool AI securing $45M in

Bitget-RWA2025/12/14 01:50
New Prospects in STEM Learning and Career Advancement: Sustained Institutional Commitment to Academic Initiatives Fueling Tomorrow’s Innovation
© 2025 Bitget