Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesEarnWeb3SquareMore
Trade
Spot
Buy and sell crypto with ease
Margin
Amplify your capital and maximize fund efficiency
Onchain
Going Onchain, without going Onchain!
Convert & block trade
Convert crypto with one click and zero fees
Explore
Launchhub
Gain the edge early and start winning
Copy
Copy elite trader with one click
Bots
Simple, fast, and reliable AI trading bot
Trade
USDT-M Futures
Futures settled in USDT
USDC-M Futures
Futures settled in USDC
Coin-M Futures
Futures settled in cryptocurrencies
Explore
Futures guide
A beginner-to-advanced journey in futures trading
Futures promotions
Generous rewards await
Overview
A variety of products to grow your assets
Simple Earn
Deposit and withdraw anytime to earn flexible returns with zero risk
On-chain Earn
Earn profits daily without risking principal
Structured Earn
Robust financial innovation to navigate market swings
VIP and Wealth Management
Premium services for smart wealth management
Loans
Flexible borrowing with high fund security
Thousands of records related to Indian bank transfers discovered on the internet

Thousands of records related to Indian bank transfers discovered on the internet

Bitget-RWA2025/09/26 09:15
By:Bitget-RWA

A misconfigured cloud server has resulted in the leak of hundreds of thousands of confidential bank transfer records in India, exposing account details, transaction amounts, and personal contact information.

Cybersecurity experts from UpGuard found a publicly accessible Amazon cloud storage server in late August, which contained 273,000 PDF files associated with bank transfers for Indian clients. 

The compromised documents were completed transaction forms meant for processing through the National Automated Clearing House (NACH), a centralized platform in India that handles large-scale recurring payments like payroll, loan installments, and utility bills.

According to the researchers, the leaked data was associated with at least 38 banks and financial organizations, as reported to TechCrunch.

The reason for the data being left open to the public remains unknown, but such incidents often occur due to configuration mistakes or human oversight.

However, it is still uncertain who was responsible for the exposure, who took steps to secure the data, and who should notify those affected by the breach.

Data is now protected, but accountability is lacking

In a blog post outlining their discovery, UpGuard’s team noted that over half of a 55,000-document sample referenced Aye Finance, an Indian lender that applied for a $171 million IPO last year. The State Bank of India, a government-owned institution, was the next most frequently mentioned in the sample, according to their findings.

Upon identifying the leak, UpGuard contacted Aye Finance via its corporate, customer support, and grievance redressal email addresses. The team also notified the National Payments Corporation of India (NPCI), which oversees NACH.

By the start of September, the researchers observed that the server remained exposed, with thousands of new files being uploaded each day. 

UpGuard then reached out to CERT-In, India’s computer emergency response team. Soon after, the server was secured, the researchers informed TechCrunch.

Yet, no organization has stepped forward to accept responsibility for the breach.

When asked for a statement, NPCI spokesperson Ankur Dahiya told TechCrunch that the leaked data did not originate from NPCI’s infrastructure.

“A thorough review and verification have established that no NACH mandate data or records from NPCI’s systems were exposed or compromised,” the spokesperson wrote in an email to TechCrunch.

Sanjay Sharma, co-founder and CEO of Aye Finance, did not reply to TechCrunch’s request for comment. The State Bank of India also did not respond to inquiries.

0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

PoolX: Earn new token airdrops
Lock your assets and earn 10%+ APR
Lock now!

You may also like

Hong Kong's move to apply 'Basel-like' standards to stablecoins ignites debate between regulation and innovation

- Hong Kong’s 2025 stablecoin rules require 100% collateralization, liquidity coverage, and T+0 redemption, aligning issuers with bank-like standards. - DBS CEO warns regulations will limit stablecoin use in DeFi derivatives, prioritizing stability over innovation despite enhanced transparency. - Market activity declined post-implementation, with small issuers exiting and Ant International pursuing a licensing advantage. - Hong Kong’s framework contrasts with Singapore’s flexible approach and U.S. proposal

Bitget-RWA2025/09/26 11:03
Hong Kong's move to apply 'Basel-like' standards to stablecoins ignites debate between regulation and innovation

Phantom inspections and inadequate safeguards drive DeFi’s newest $3.6 million exit fraud

- DeFi platform HyperVault suffered a $3.6M rug pull, with funds siphoned via Hyperliquid to Ethereum and Tornado Cash. - Project’s deleted social media accounts and fake audit claims exposed lack of transparency in DeFi protocols. - 752 ETH ($3M) laundered through privacy mixers highlights need for dual wallets and AI monitoring to detect suspicious patterns. - Community warnings ignored as unverified audits and aggressive yield marketing prioritized over security in competitive DeFi ecosystems. - Inciden

Bitget-RWA2025/09/26 11:03
Phantom inspections and inadequate safeguards drive DeFi’s newest $3.6 million exit fraud

Hong Kong's KYC Requirement Sets Regulation in Opposition to DeFi Advancement

- Hong Kong's new stablecoin KYC/AML rules, effective August 2025, require identity checks for all holders and licensing for issuers, diverging from blockchain's anonymity norms. - DBS Hong Kong CEO Sebastian Paredes warns these regulations could stifle DeFi innovation by deterring stablecoin integration into decentralized derivatives platforms. - HKMA mandates 100% high-quality reserves, real-time redemption, and Basel-like liquidity buffers for stablecoin issuers, raising compliance costs and favoring la

Bitget-RWA2025/09/26 11:03
Hong Kong's KYC Requirement Sets Regulation in Opposition to DeFi Advancement

Hilbert Views Concordium as a Link Connecting Traditional Finance and Regulatory-Compliant DeFi Systems

- Hilbert Group invests in Concordium's CCD token, its first core allocation beyond Bitcoin and Ethereum, citing confidence in its institutional-grade blockchain infrastructure. - Concordium's identity-verified blockchain with zero-knowledge privacy supports 2,000 TPS and PayFi features like geofencing, addressing scalability and compliance for enterprise use. - The partnership accelerates institutional adoption of blockchain bridging TradFi and DeFi, leveraging Concordium's MiCA/GENIUS Act alignment and c

Bitget-RWA2025/09/26 10:30
Hilbert Views Concordium as a Link Connecting Traditional Finance and Regulatory-Compliant DeFi Systems