Data breach on Indian mobile payment app BHIM exposes 7 million records


A data breach on a government-promoted payments app BHIM in India has resulted in some highly sensitive personal data of over 70 million people getting exposed. The vulnerability and the data exposure was brought to the fore by an Israeli cybersecurity company.
The CSC BHIM website is used for financial transactions through a unified payment interface (UPI) as part of the federal government’s digital access initiatives in the villages. The BHIM project was initially launched to drive digital payments for merchants across rural India. The app was developed by the National Payment Corporation of India, a state-owned enterprise.
Israeli cybersecurity agency vpnMentor, which found the data breach, said more than 400 GB of user data was compromised and these included details of Aadhar registrations, caste certificates and other personal data that could be used to identify people and businesses.
The company claimed that the hacker would now possess complete data of users and likened it to gaining access to the data infrastructure of a bank with all user account information. It said the vulnerability was first detected on April 23 and was reportedly fixed nearly a month later on May 22.
Though there is no evidence to point out that the BHIM app itself was leaking data or that the UPI system was insecure, the security agency says that some more research is required to highlight the vulnerabilities so that future threats can be avoided.
Ironically, news of the breach comes when #CSCSocialMediaDay has been trending on Twitter.
#CSCSocialMediaDay #CSCSocialMediaDayCSC is my identity. It gives me everything.I am proud to be a part of CSC.@CSCegov_ @dintya15 @wifichoupal @CSCMaharashtra @CSCNashik @rsprasad @Swapnil66864291 @maheshkolte15 @Gaurav08Pawar pic.twitter.com/lYwgbOr5cdJune 1, 2020
In the report, vpmMentor says the data collected for deploying the BHIM app was stored on a mis-configured Amazon Web Services S3 bucket that was accessible publicly. This, the agency said, is a common error that many companies do when setting up their cloud systems. The data that lay unsecured amounted to 409 GB and contained information about individuals and several merchants.
The UPI payment system is similar to a bank account and is valuable to hackers in general. It gives them access to vast amounts of information about a person’s finances and bank accounts, which can then be used to illegally access them and make fraudulent transactions.
The statement from vpnMentor research team said it discovered the misconfiguration in CSC’s S3 bucket as part of a huge web mapping project. “Our researchers use port scanning to examine particular IP blocks and test different systems for weaknesses or vulnerabilities. They examine each weakness for any data being exposed,” the report said.
This is not the first time that vulnerability issues have been by third-parties around apps in India. The Covid-19 tracing app Aarogya Setu saw several such reports including an ethical hacker in Bangalore who claimed he broke into the system in a very short time. The administration took cognisance of these reports and offered a bugs bounty program after sharing the code base on public domains like GitHub.
A data breach on a government-promoted payments app BHIM in India has resulted in some highly sensitive personal data of over 70 million people getting exposed. The vulnerability and the data exposure was brought to the fore by an Israeli cybersecurity company. The CSC BHIM website is used for financial…
Recent Posts
Archives
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010