Firstpost
  • Home
  • Video Shows
    Vantage Firstpost America Firstpost Africa First Sports
  • World
    US News
  • Explainers
  • News
    India Opinion Cricket Tech Entertainment Sports Health Photostories
  • Asia Cup 2025
Apple Incorporated Modi ji Justin Trudeau Trending

Sections

  • Home
  • Live TV
  • Videos
  • Shows
  • World
  • India
  • Explainers
  • Opinion
  • Sports
  • Cricket
  • Health
  • Tech/Auto
  • Entertainment
  • Web Stories
  • Business
  • Impact Shorts

Shows

  • Vantage
  • Firstpost America
  • Firstpost Africa
  • First Sports
  • Fast and Factual
  • Between The Lines
  • Flashback
  • Live TV

Events

  • Raisina Dialogue
  • Independence Day
  • Champions Trophy
  • Delhi Elections 2025
  • Budget 2025
  • US Elections 2024
  • Firstpost Defence Summit
Trending:
  • Charlie Kirk shot dead
  • Nepal protests
  • Russia-Poland tension
  • Israeli strikes in Qatar
  • Larry Ellison
  • Apple event
  • Sunjay Kapur inheritance row
fp-logo
BHIM app vulnerability reportedly exposed financial data of millions of users; NPCI denies data compromise
Whatsapp Facebook Twitter
Whatsapp Facebook Twitter
Apple Incorporated Modi ji Justin Trudeau Trending

Sections

  • Home
  • Live TV
  • Videos
  • Shows
  • World
  • India
  • Explainers
  • Opinion
  • Sports
  • Cricket
  • Health
  • Tech/Auto
  • Entertainment
  • Web Stories
  • Business
  • Impact Shorts

Shows

  • Vantage
  • Firstpost America
  • Firstpost Africa
  • First Sports
  • Fast and Factual
  • Between The Lines
  • Flashback
  • Live TV

Events

  • Raisina Dialogue
  • Independence Day
  • Champions Trophy
  • Delhi Elections 2025
  • Budget 2025
  • US Elections 2024
  • Firstpost Defence Summit
  • Home
  • Tech
  • News & Analysis
  • BHIM app vulnerability reportedly exposed financial data of millions of users; NPCI denies data compromise

BHIM app vulnerability reportedly exposed financial data of millions of users; NPCI denies data compromise

Press Trust of India • June 2, 2020, 15:17:17 IST
Whatsapp Facebook Twitter

According to Vpnmentor, the 409 GB of data suspected to be breached has over 70 lakh records.

Advertisement
Subscribe Join Us
Add as a preferred source on Google
Prefer
Firstpost
On
Google
BHIM app vulnerability reportedly exposed financial data of millions of users; NPCI denies data compromise

A group of ethical hackers on Monday claimed to have discovered a vulnerability affecting millions of BHIM app users, a claim which was denied by NPCI that operates the small value payments application. Vpnmentor, which claimed to be the largest virtual private networks review website offering a research lab that helps the online community defend itself against cyber threats, alleged that there has been a “data leak” discovered with respect to that of the users of the payments app. The group also said that an Indian government website focused on pushing adoption of BHIM has exposed data of millions of users to potential fraud. [caption id=“attachment_6523621” align=“alignnone” width=“1024”]Representational image. Image: Tech2 Representational image. Image: Tech2[/caption] The National Payments Corporation of India (NPCI) said there has been no data compromise at the BHIM App, which has over 136 million downloads. “The developers of the CSC/BHIM website could have easily avoided exposing user data if they had taken some basic security measures to protect the data,” Vpnmentor said in a statement. The Ministry of Electronics and Information Technology has an initiative called CSC (Common Services Centre)-BHIM, which has a portal used by field agents as part of a campaign to push the adoption of the BHIM app, by merchants and also the general public. According to Vpnmentor, data from this campaign was being stored on a “misconfigured Amazon Web Services S3 bucket” and was publicly accessible, making it vulnerable to misuse for executing frauds, thefts and attack from hackers and cyber criminals. It also termed the scale of the exposed data as “extraordinary”, and pegged the number of users exposed in “millions”, adding that the 409 GB of data suspected to be breached has over 70 lakh records. “We would like to clarify that there has been no data compromise at BHIM App and request everyone to not fall prey to such speculations. NPCI follows high level of security and an integrated approach to protect its infrastructure and continue to provide a robust payments ecosystem,” the NPCI said in a statement. The app was launched in 2016. The breach was discovered on April 23 and the Indian Computer Emergency Response Team was contacted on 28 April. The CERT-IN responded the very next day and 22 May has been noted as the date of action in Vpnmentor’s report. Over 70 lakh users’ data uploaded in February was exposed, the report said, adding the records which were exposed online included scans of Aadhaar cards, caste certificates, residence proofs, professional certificates and degrees, screenshots of fund transfers and PAN cards. The private personal user data within these documents gave a complete profile of individuals, their finances, and banking records, it noted. In the statement issued by Vpnmentor, its cyber security researchers Noam Rotem and Ran Locar said the sheer volume of sensitive, private data exposed, along with UPI IDs, document scans, and more, makes this breach deeply concerning. “The exposure of BHIM user data is akin to a hacker gaining access to the entire data infrastructure of a bank, along with millions of its users’’ account information,” they said in the statement.

Tags
User data CERT In cybersecurity BHIM app Ministry of Electronics and Information Technology National Payments Corporation of India NCPI Vpnmentor
End of Article
Latest News
Find us on YouTube
Subscribe
End of Article

Top Stories

Charlie Kirk, shot dead in Utah, once said gun deaths are 'worth it' to save Second Amendment

Charlie Kirk, shot dead in Utah, once said gun deaths are 'worth it' to save Second Amendment

From governance to tourism, how Gen-Z protests have damaged Nepal

From governance to tourism, how Gen-Z protests have damaged Nepal

Did Russia deliberately send drones into Poland’s airspace?

Did Russia deliberately send drones into Poland’s airspace?

Netanyahu ‘killed any hope’ for Israeli hostages: Qatar PM after Doha strike

Netanyahu ‘killed any hope’ for Israeli hostages: Qatar PM after Doha strike

Charlie Kirk, shot dead in Utah, once said gun deaths are 'worth it' to save Second Amendment

Charlie Kirk, shot dead in Utah, once said gun deaths are 'worth it' to save Second Amendment

From governance to tourism, how Gen-Z protests have damaged Nepal

From governance to tourism, how Gen-Z protests have damaged Nepal

Did Russia deliberately send drones into Poland’s airspace?

Did Russia deliberately send drones into Poland’s airspace?

Netanyahu ‘killed any hope’ for Israeli hostages: Qatar PM after Doha strike

Netanyahu ‘killed any hope’ for Israeli hostages: Qatar PM after Doha strike

Top Shows

Vantage Firstpost America Firstpost Africa First Sports
Latest News About Firstpost
Most Searched Categories
  • Web Stories
  • World
  • India
  • Explainers
  • Opinion
  • Sports
  • Cricket
  • Tech/Auto
  • Entertainment
  • IPL 2025
NETWORK18 SITES
  • News18
  • Money Control
  • CNBC TV18
  • Forbes India
  • Advertise with us
  • Sitemap
Firstpost Logo

is on YouTube

Subscribe Now

Copyright @ 2024. Firstpost - All Rights Reserved

About Us Contact Us Privacy Policy Cookie Policy Terms Of Use
Home Video Shorts Live TV