NewsBytes Stage
    Hindi
    More
    In the news
    Narendra Modi
    Amit Shah
    Box Office Collection
    Bharatiya Janata Party (BJP)
    OTT releases
    Hindi
    NewsBytes Stage
    India
    Business
    World
    Politics
    Sports
    Technology
    Entertainment
    Auto
    Lifestyle
    Career
    Visual Stories
    Find Cricket Statistics

    Download Android App

    Follow us on
    • Facebook
    • Twitter
    • Linkedin
    Home / News / Technology News / #LeakAlert: Data of 7 million+ BHIM users exposed
    Next Article
    #LeakAlert: Data of 7 million+ BHIM users exposed

    #LeakAlert: Data of 7 million+ BHIM users exposed

    By Shubham Sharma
    Jun 01, 2020
    11:33 pm

    What's the story

    Personal and financial data of more than 7 million users of BHIM, a government-backed peer-to-peer UPI payments app, has been leaked publicly.

    The data was exposed through an unprotected server, which was discovered and reported by researchers at vpnMentor to the Indian authorities.

    Now, it has been secured, the company said in a blog post.

    Here are all the details.

    Leak

    Leak through CSC BHIM website

    When BHIM was launched in 2016, a CSC website (http://cscbhim.in/) was created as part of a campaign to bring as many users and merchants as possible to the app.

    All the data collected through this campaign, estimated to be 409GB in size, was stored on an Amazon Web Services S3 bucket and left unprotected, open to be accessed/downloaded by anyone knowing where to look.

    Details

    What kind of data it included?

    As spotted by vpnMentor in April, the unprotected bucket had 7.26 million user records, which included Aadhaar cards, caste certificates, address proofs, professional certificates, college degrees, and Permanent account numbers (PANs), and screenshots taken to show successful fund transfers.

    The information included in these documents could have easily been used by attackers to create a whole profile of individuals and target them with scams.

    Action

    Action taken after multiple warnings

    Initially, the vpnMentor team tried contacting CSC e-Governance Services, the developer of the CSC BHIM website and the owner of the S3 bucket, but did not receive a response.

    Then, multiple reports were sent to India's Computer Emergency Response Team (CERT-In), following which the unprotected AWS bucket was secured, and the data was no longer being exposed.

    Response

    What NPCI, BHIM's developer, says on the matter

    The National Payments Corporation of India (NCPI), which developed the BHIM app, says that the exposure does not relate to the app data.

    "There has been no data compromise at BHIM App. NPCI follows a high level of security and an integrated approach to protect its infrastructure and continue to provide a robust payments ecosystem," it said in a statement quoted by Economic Times.

    Information

    No clarity over who accessed the bucket

    That being said, it must also be noted that as of now, it is not clear if anyone had accessed the unprotected Amazon bucket before it was plugged or not.

    Facebook
    Whatsapp
    Twitter
    Linkedin
    Related News
    Latest
    Security
    Amazon
    National Payments Corporation of India
    Amazon Web Services

    Latest

    Bangladesh Cricket Board pondering over Bangladesh's tour of Pakistan Bangladesh Cricket Board
    Why Virat Kohli's presence could lift India in England? Stats Virat Kohli
    Google Workspace accounts gain access to Gemini Live feature Google
    Adani Group deploys India's 1st hydrogen-powered truck in Chhattisgarh Adani Group

    Security

    Facebook tracks you regularly - how to stop it? Facebook
    Zoom flaw could have let anyone hijack video conference calls United States of America
    Thousands of Instagram passwords leaked: Details here Instagram
    Avast shutting down company that sold user data without permission Microsoft

    Amazon

    Is government planning to censor streaming platforms Narendra Modi
    How this guy turned a rotary phone into Google Assistant Reddit
    Samsung Galaxy M30s gets a new 4GB/128GB variant: Details here Samsung
    #DealOfTheDay: Xiaomi's wallet-friendly Redmi Note 8 available with exciting offers Xiaomi

    National Payments Corporation of India

    A data leak and an earthquake mar this week India
    The story of the security team behind the BHIM app India
    45 people become lakhpatis under NPCI schemes NITI Aayog
    Banks free to fix charges on cashless transactions RuPay

    Amazon Web Services

    Succumbing to cloud rivals, Rackspace goes private in an acquisition Morgan Stanley
    Amazon posts third-quarter earnings; misses estimates Amazon
    Database can help Mumbaiites to watch out for sex-offenders Mumbai
    Microsoft mulls on investing $100 million in Ola's parent firm India
    Indian Premier League (IPL) Celebrity Hollywood Bollywood UEFA Champions League Tennis Football Smartphones Cryptocurrency Upcoming Movies Premier League Cricket News Latest automobiles Latest Cars Upcoming Cars Latest Bikes Upcoming Tablets
    About Us Privacy Policy Terms & Conditions Contact Us Ethical Conduct Grievance Redressal News News Archive Topics Archive Download DevBytes Find Cricket Statistics
    Follow us on
    Facebook Twitter Linkedin
    All rights reserved © NewsBytes 2025