Close Menu
    Facebook X (Twitter) Instagram
    • Home
    • About Us
    • Digital Subscription
    • Advertisement
    • Contact Us
    Facebook X (Twitter) Instagram
    The Tennessee TribuneThe Tennessee Tribune
    Advertise With Us
    • Home
      • COVID-19 Resource Center
        • Dr. Henry Louis Gates’ PSA Radio
      • Featured
    • News
      • State
      • Local
      • National/International News
      • Global
      • Business
        • Commentary
        • Finance
        • Local Business
      • Investigative Stories
        • Affordable Housing
        • DCS Investigation
        • Gentrification
    • Editorial
      • National Politics
      • Local News
      • Local Editorial
      • Political Editorial
      • Editorial Cartoons
      • Cycle of Shame
    • Community
      • History
      • Tennessee
        • Chattanooga
        • Clarksville
        • Knoxville
        • Memphis
      • Public Notices
      • Women
        • Let’s Talk with Ms. June
    • Education
      • College
        • American Baptist College
        • Belmont University
        • Fisk
        • HBCU
        • Meharry
        • MTSU
        • University of Tennessee
        • TSU
        • Vanderbilt
      • Elementary
      • High School
    • Lifestyle
      • Art
      • Auto
      • Tribune Travel
      • Entertainment
        • 5 Questions With
        • Books
        • Events
        • Film Review
        • Local Entertainment
      • Family
      • Food
        • Drinks
      • Health & Wellness
      • Home & Garden
      • Featured Books
    • Religion
      • National Religion
      • Local Religion
      • Obituaries
        • National Obituaries
        • Local Obituaries
      • Faith Commentary
    • Sports
      • MLB
        • Sounds
      • NBA
      • NCAA
      • NFL
        • Predators
        • Titans
      • NHL
      • Other Sports
      • Golf
      • Professional Sports
      • Sports Commentary
      • Metro Sports
    • Media
      • Video
      • Photo Galleries
      • Take 10
      • Trending With The Tribune
    • Classified
    • Obituaries
      • Local Obituaries
      • National Obituaries
    The Tennessee TribuneThe Tennessee Tribune
    National/International News

    Indian Brokerage Firm Upstox Suffers Massive Data Breach

    zenger.newsBy zenger.newsApril 22, 2021No Comments6 Mins Read
    Facebook Twitter LinkedIn Telegram Pinterest Tumblr Reddit Email
    Share
    Facebook Twitter LinkedIn Pinterest Email

    CHENNAI, India — India’s second-largest stockbroking firm Upstox initiated password resets for millions of traders on its platform earlier this month after learning a huge data breach might have hit it.

    Chief executive Ravi Kumar announced on April 11 some user data and Know-Your-Customer details — that all financial services firms in India accept to verify user identity — might have been compromised from third-party data-warehouse systems.

    “We have upgraded our security systems manifold recently, on the recommendations of a global cyber-security firm,” Kumar, co-founder of the firm backed by the likes of investment firm Tiger Global Management and Indian industrialist Ratan Tata, said in a statement.

    “We would like to assure you that your funds and securities are protected and remain safe. Funds can only be moved to your linked bank accounts, and your securities are held with the relevant depositories.”

    “As a matter of abundant caution, we have also initiated a secure password reset via One-Time Password.” The start-up, which began in 2012, has raised around $29 million in funding, according to Crunchbase.

    “About 80-90 percent of companies are breached because Amazon Web Services keys are compromised,” internet security researcher Rajshekhar Rajaharia said. (Sean Gallup/Getty Images)

    While the statement did not disclose the number of user accounts affected in the breach, independent internet security researcher Rajshekhar Rajaharia told Zenger News sensitive data of “almost 2.5 million users were compromised”.

    “There’s a forum on the dark web, and it [Upstox data] was posted there asking for $1.2 million in ransom along with data of 100,000 users on Sunday,” Rajaharia said.

    “The breach had names, emails, passwords, bank details, KYC soft copies including signatures — which is huge. In data breaches, if your card details are stolen, you can apply for a new one, but you can’t change your signature.”

    Upstox’s spokesperson told Zenger News the firm had initiated multiple security enhancements, particularly at the third-party warehouses, real-time 24×7 monitoring, and additional ring-fencing.

    “Upstox takes customer security extremely seriously,” the spokesperson said in an email to Zenger News. “Funds and securities of all Upstox customers are protected and remain safe. We have also duly reported this incident to the relevant authorities.”

    On April 13, reports of a data breach at cloud communication platform provider Route Mobile spread. But the firm denied the claims.

    “We would like to highlight that unverified posts and claims are being circulated about an alleged data breach at Route Mobile,” Upstox spokesperson said in an email to Zenger News. “Our cybersecurity team is investigating the same.”

    “As of today, we can confirm that Route Mobile’s systems are secure, and there is no evidence to suggest that this has any impact on Route Mobile customers’ personal data. As we take all data security claims seriously, we have engaged a third-party cybersecurity consultant to verify and audit our findings independently,” the spokesperson said.

    Another financial services firm, MobiKwik, took the same route and denied any data breach the previous month. The firm went on to blame users. Reports claim hackers exposed data of 110 million of the firm’s 120 million users.

    “There’s a forum on the dark web, and it [Upstox data] was posted there asking for $1.2 million in ransom along with data of 100,000 users on Sunday,” Rajaharia said. (Soumil Kumar from Pexels)

    “Some users have reported that their data is visible on the dark web. While we are investigating this, it is entirely possible that any user could have uploaded her/his information on multiple platforms. Hence, it is incorrect to suggest that the data available on the dark web has been accessed from MobiKwik,” a note from MobiKwik states.

    Rajaharia says Upstox’s Amazon Web Services key was compromised in the breach, the same reason for the MobiKwik breach.

    “About 80-90 percent of companies are breached because Amazon Web Services keys are compromised,” Rajaharia told Zenger News.

    “There can be a lot of reasons for this. Some employees use company email ID in other sites, and if those sites are breached, keys can be easily compromised.”

    Advertisement

    “Work-from-home could be another reason. Inside an office, you have protection and a firewall, but hackers can easily target servers at home. There have been a lot of breaches post-Covid,” he said.

    Upstox data breach comes when networking platform Facebook saw a data leak of 530 million users and LinkedIn had the data of 500 million users compromised.

    In India, payment gateway Juspay’s data breach affected 35 million users. E-grocer BigBasket confirmed a data breach last year after cyber intelligence firm Cyble said 20 million users were affected and sensitive data leaked. The firm filed a First Information Report with the Bengaluru Police in November 2020 to investigate the incident.

    Last year, online edutech firm Unacademy suffered a data breach of 20 million users, with hackers selling the information for $2,000, according to Cyble. Unacademy maintained that the breach impacted only 11 million users of the platform, and no passwords were exposed.

    Rajaharia believes “hacker group ShinyHunters was responsible for the Upstox breach and was behind the hacking of Juspay, BigBasket, and Unacademy”.

    In another tweet, he said: “It seems after this alleged Upstox data breach, ShinyHunters email account has been suspended. According to Wikipedia, ShinyHunters group is under investigation from the FBI, the Indonesian police, and the Indian police.”

    Unlike companies in the U.S., Indian firms are not obligated to disclose data breaches publicly. They are only expected to report breaches, identity thefts, and phishing attacks to the Indian Computer Emergency Response Team (CERT-In). CERT is a nodal agency under the India’s Ministry of Electronics and Information Technology that handles cybersecurity-related issues.

    CERT-In did not respond to Zenger News’ queries on the Upstox data breach.

    “India is yet to build specific legislation around data protection,” advocate Satyoki Koundinya, who practices in the areas of IT, telecommunication, and IP law, told Zenger News. “However, certain direct and indirect laws and regulations exist.”

    Among these are the CERT-In Rules of 2013 and the Personal Data Protection Bill of 2019, which has provisions to deal with data breaches but is yet to be made into law.

    “CERT-In Rules of 2013 imposes mandatory notification requirements on service providers, intermediaries, data centers, and corporate entities upon the occurrence of any breach,” Koundinya said.

    The Personal Data Protection Bill of 2019 includes provisions like the appointment of a data protection officer, notification of a breach to individuals after the determination of the nature of the breach by CERT-In, and a 2-4 percent global turnover as a penalty for breaches.

    “The bill offers similar protection and more stringent compliance, especially with regard to the processing of sensitive personal data, including requiring explicit consent, imposing additional conditions for cross-border transfers, and requiring a copy to be stored in India,” advocate Koundinya said.

    Japan was the top attacked country in Asia in 2020, followed distantly by India and Australia, according to a report from IBM Security. Data theft was the most common attack type in Asia in 2020, followed by ransomware.

    (Edited by Amrita Das and Gaurab Dasgupta)



    The post Indian Brokerage Firm Upstox Suffers Massive Data Breach appeared first on Zenger News.

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    zenger.news
    • Website

    Related Posts

    The Department of Education is Collecting Delinquent Student Loan Debt

    April 29, 2025

    Benjamin F. Chavis Jr.Chavis and Bryant Lead Charge as Target Boycott Grows

    April 29, 2025

    Black Think Tank Challenges Big Tech’s Legal Armor

    April 29, 2025

    Trump Signs New HBCU Executive Order

    April 29, 2025

    Civil Rights Groups to White House: ‘We Won’t Back Down’

    April 29, 2025

    Black Health Jeopardized as FDA Scraps Milk Oversight

    April 29, 2025

    Comments are closed.

    Business

    FUNdraising Good Times Survival through partnerships, collaborations, and mergers

    May 14, 2025

    Target Boycotts and its Effect on Both Sides of the Black Dollar

    May 6, 2025

    FedEx to Launch FedEx Easy Returns at 3,000 Locations Across the US, Supported by Blue Yonder

    May 2, 2025
    1 2 3 … 382 Next
    Education
    Education

    From Stratford to Harvard: GEAR UP Student Earns Full Scholarship to Ivy League School

    By Tribune StaffMay 14, 2025

    Once Isioma Ikhile opened the application portal on her phone and saw the news, she…

    Austin Peay State University graduates 1,400 students at Spring 2025 commencement

    May 14, 2025

    MTSU College of Media and Entertainment adds 4 alums to prestigious ‘Wall of Fame’

    May 14, 2025

    TSU names new interim directors for Aristocrat of Bands, and Cheer and Dance Group

    May 11, 2025
    The Tennessee Tribune
    Facebook X (Twitter) Instagram
    • About Us
    • Digital Subscription
    • Store
    • Advertise With Us
    • Contact
    © 2025 The Tennessee Tribune - Site Designed by No Regret Media.

    Type above and press Enter to search. Press Esc to cancel.

    Our Spring Sale Has Started

    You can see how this popup was set up in our step-by-step guide: https://wppopupmaker.com/guides/auto-opening-announcement-popups/