{"id":1300720,"date":"2025-09-27T08:34:47","date_gmt":"2025-09-27T03:04:47","guid":{"rendered":"https:\/\/trak.in\/stories\/?p=1300720"},"modified":"2025-09-27T08:35:54","modified_gmt":"2025-09-27T03:05:54","slug":"27-lakh-bank-transfer-records-exposed-sbi-aye-finance-most-impacted","status":"publish","type":"post","link":"https:\/\/trak.in\/stories\/27-lakh-bank-transfer-records-exposed-sbi-aye-finance-most-impacted\/","title":{"rendered":"27 Lakh Bank Transfer Records Exposed: SBI, Aye Finance Most Impacted"},"content":{"rendered":"\n<p>In a significant cybersecurity lapse, a massive trove of sensitive bank transfer documents belonging to Indian customers was left publicly accessible online, exposing critical financial and personal information. The data leak, discovered by cybersecurity firm UpGuard, was traced back to an unsecured Amazon S3 storage server.<\/p>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"1000\" height=\"465\" src=\"https:\/\/trak.in\/stories\/wp-content\/uploads\/2025\/09\/Malvika-3-1.jpeg\" alt=\"27 Lakh Bank Transfer Records Exposed: SBI, Aye Finance Most Impacted\" class=\"wp-image-1300729\" srcset=\"https:\/\/trak.in\/stories\/wp-content\/uploads\/2025\/09\/Malvika-3-1.jpeg 1000w, https:\/\/trak.in\/stories\/wp-content\/uploads\/2025\/09\/Malvika-3-1-300x140.jpeg 300w, https:\/\/trak.in\/stories\/wp-content\/uploads\/2025\/09\/Malvika-3-1-768x357.jpeg 768w\" sizes=\"auto, (max-width: 1000px) 100vw, 1000px\" \/><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">Sensitive Banking Data Left Exposed<\/h3>\n\n\n\n<p>The exposed database contained over <strong><a href=\"https:\/\/techcrunch.com\/2025\/09\/26\/thousands-of-indian-bank-transfer-records-found-online\/\">273,000 PDF documents<\/a><\/strong> related to National Automated Clearing House (NACH) transactions \u2014 a system used by banks for high-volume payments like salaries, EMIs, and utility bills. The documents revealed sensitive details such as <strong>bank account numbers, transaction amounts, and customer contact information<\/strong>, linked to at least <strong>38 banks and financial institutions<\/strong>.<\/p>\n\n\n\n<p>Among the documents, <strong>Aye Finance<\/strong> and the <strong>State Bank of India (SBI)<\/strong> appeared most frequently, according to UpGuard\u2019s findings.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Leak Persisted for Weeks Despite Alerts<\/h3>\n\n\n\n<p>UpGuard researchers discovered the unsecured server in late August and immediately alerted Aye Finance, the National Payments Corporation of India (NPCI), and India\u2019s cybersecurity agency, <strong>CERT-In<\/strong>. However, by early September, the server remained exposed, and new files were still being uploaded daily.<\/p>\n\n\n\n<p>It was only after CERT-In\u2019s involvement that the server was finally secured, though by then the data had already been indexed online, increasing the risk of unauthorized access.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Nupay Admits Responsibility but Downplays Impact<\/h3>\n\n\n\n<p>Following the exposure, Indian fintech startup <strong>Nupay<\/strong> confirmed that the leak originated from a misconfigured Amazon S3 bucket. The company claimed that only a \u201climited set of test records\u201d was involved and that there was \u201cno unauthorized access or misuse.\u201d<\/p>\n\n\n\n<p>However, UpGuard <strong>disputed Nupay\u2019s claims<\/strong>, stating that most of the files contained real customer data and that Nupay had not requested the researchers\u2019 IP logs to verify access details. Additionally, the public server\u2019s address had been indexed on <strong>Grayhatwarfare<\/strong>, a database known for listing exposed cloud storage.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">A Wake-Up Call for India\u2019s Fintech Sector<\/h3>\n\n\n\n<p>The incident underscores the growing risks associated with misconfigured cloud storage and highlights the urgent need for stricter <strong>data security and compliance standards<\/strong> in India\u2019s rapidly expanding fintech ecosystem.<\/p>\n\n\n\n<p>While the breach has now been plugged, questions remain about how long the data was exposed and whether it was accessed by malicious actors \u2014 a concern that could have significant financial and legal consequences.<\/p>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>In a significant cybersecurity lapse, a massive trove of sensitive bank transfer documents belonging to Indian customers was left publicly accessible online, exposing critical financial and personal information. The data leak, discovered by cybersecurity firm UpGuard, was traced back to an unsecured Amazon S3 storage server. Sensitive Banking Data Left Exposed The exposed database contained [&hellip;]<\/p>\n","protected":false},"author":30,"featured_media":1300729,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[],"class_list":["post-1300720","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v25.9 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>27 Lakh Bank Transfer Records Exposed: SBI, Aye Finance Most Impacted - Trak.in - Indian Business of Tech, Mobile &amp; Startups<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/trak.in\/stories\/27-lakh-bank-transfer-records-exposed-sbi-aye-finance-most-impacted\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"27 Lakh Bank Transfer Records Exposed: SBI, Aye Finance Most Impacted - Trak.in - Indian Business of Tech, Mobile &amp; Startups\" \/>\n<meta property=\"og:description\" content=\"In a significant cybersecurity lapse, a massive trove of sensitive bank transfer documents belonging to Indian customers was left publicly accessible online, exposing critical financial and personal information. The data leak, discovered by cybersecurity firm UpGuard, was traced back to an unsecured Amazon S3 storage server. Sensitive Banking Data Left Exposed The exposed database contained [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/trak.in\/stories\/27-lakh-bank-transfer-records-exposed-sbi-aye-finance-most-impacted\/\" \/>\n<meta property=\"og:site_name\" content=\"Trak.in - Indian Business of Tech, Mobile &amp; Startups\" \/>\n<meta property=\"article:published_time\" content=\"2025-09-27T03:04:47+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-09-27T03:05:54+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/trak.in\/stories\/wp-content\/uploads\/2025\/09\/Malvika-3-1.jpeg\" \/>\n\t<meta property=\"og:image:width\" content=\"1000\" \/>\n\t<meta property=\"og:image:height\" content=\"465\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Mohul Ghosh\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Mohul Ghosh\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/trak.in\/stories\/27-lakh-bank-transfer-records-exposed-sbi-aye-finance-most-impacted\/\",\"url\":\"https:\/\/trak.in\/stories\/27-lakh-bank-transfer-records-exposed-sbi-aye-finance-most-impacted\/\",\"name\":\"27 Lakh Bank Transfer Records Exposed: SBI, Aye Finance Most Impacted - Trak.in - Indian Business of Tech, Mobile &amp; Startups\",\"isPartOf\":{\"@id\":\"https:\/\/trak.in\/stories\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/trak.in\/stories\/27-lakh-bank-transfer-records-exposed-sbi-aye-finance-most-impacted\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/trak.in\/stories\/27-lakh-bank-transfer-records-exposed-sbi-aye-finance-most-impacted\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/trak.in\/stories\/wp-content\/uploads\/2025\/09\/Malvika-3-1.jpeg\",\"datePublished\":\"2025-09-27T03:04:47+00:00\",\"dateModified\":\"2025-09-27T03:05:54+00:00\",\"author\":{\"@id\":\"https:\/\/trak.in\/stories\/#\/schema\/person\/5092a7d2906e3f3c819643435477c2a7\"},\"breadcrumb\":{\"@id\":\"https:\/\/trak.in\/stories\/27-lakh-bank-transfer-records-exposed-sbi-aye-finance-most-impacted\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/trak.in\/stories\/27-lakh-bank-transfer-records-exposed-sbi-aye-finance-most-impacted\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/trak.in\/stories\/27-lakh-bank-transfer-records-exposed-sbi-aye-finance-most-impacted\/#primaryimage\",\"url\":\"https:\/\/trak.in\/stories\/wp-content\/uploads\/2025\/09\/Malvika-3-1.jpeg\",\"contentUrl\":\"https:\/\/trak.in\/stories\/wp-content\/uploads\/2025\/09\/Malvika-3-1.jpeg\",\"width\":1000,\"height\":465},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/trak.in\/stories\/27-lakh-bank-transfer-records-exposed-sbi-aye-finance-most-impacted\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/trak.in\/stories\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"27 Lakh Bank Transfer Records Exposed: SBI, Aye Finance Most Impacted\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/trak.in\/stories\/#website\",\"url\":\"https:\/\/trak.in\/stories\/\",\"name\":\"Trak.in - Indian Business of Tech, Mobile &amp; Startups\",\"description\":\"Trak.in is a popular Indian Business, Technology, Mobile &amp; Startup blog featuring trending News, views and analytical take on Technology, Business, Finance, Telecom, Mobile, startups &amp; Social Media Space\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/trak.in\/stories\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/trak.in\/stories\/#\/schema\/person\/5092a7d2906e3f3c819643435477c2a7\",\"name\":\"Mohul Ghosh\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/trak.in\/stories\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/66c129d83dd3f325a3b550eb1aa16891173ddfc4686361424206cd9a01311c89?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/66c129d83dd3f325a3b550eb1aa16891173ddfc4686361424206cd9a01311c89?s=96&d=mm&r=g\",\"caption\":\"Mohul Ghosh\"},\"url\":\"https:\/\/trak.in\/stories\/author\/mohul-ghosh\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"27 Lakh Bank Transfer Records Exposed: SBI, Aye Finance Most Impacted - Trak.in - Indian Business of Tech, Mobile &amp; Startups","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/trak.in\/stories\/27-lakh-bank-transfer-records-exposed-sbi-aye-finance-most-impacted\/","og_locale":"en_US","og_type":"article","og_title":"27 Lakh Bank Transfer Records Exposed: SBI, Aye Finance Most Impacted - Trak.in - Indian Business of Tech, Mobile &amp; Startups","og_description":"In a significant cybersecurity lapse, a massive trove of sensitive bank transfer documents belonging to Indian customers was left publicly accessible online, exposing critical financial and personal information. The data leak, discovered by cybersecurity firm UpGuard, was traced back to an unsecured Amazon S3 storage server. Sensitive Banking Data Left Exposed The exposed database contained [&hellip;]","og_url":"https:\/\/trak.in\/stories\/27-lakh-bank-transfer-records-exposed-sbi-aye-finance-most-impacted\/","og_site_name":"Trak.in - Indian Business of Tech, Mobile &amp; Startups","article_published_time":"2025-09-27T03:04:47+00:00","article_modified_time":"2025-09-27T03:05:54+00:00","og_image":[{"width":1000,"height":465,"url":"https:\/\/trak.in\/stories\/wp-content\/uploads\/2025\/09\/Malvika-3-1.jpeg","type":"image\/jpeg"}],"author":"Mohul Ghosh","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Mohul Ghosh","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/trak.in\/stories\/27-lakh-bank-transfer-records-exposed-sbi-aye-finance-most-impacted\/","url":"https:\/\/trak.in\/stories\/27-lakh-bank-transfer-records-exposed-sbi-aye-finance-most-impacted\/","name":"27 Lakh Bank Transfer Records Exposed: SBI, Aye Finance Most Impacted - Trak.in - Indian Business of Tech, Mobile &amp; Startups","isPartOf":{"@id":"https:\/\/trak.in\/stories\/#website"},"primaryImageOfPage":{"@id":"https:\/\/trak.in\/stories\/27-lakh-bank-transfer-records-exposed-sbi-aye-finance-most-impacted\/#primaryimage"},"image":{"@id":"https:\/\/trak.in\/stories\/27-lakh-bank-transfer-records-exposed-sbi-aye-finance-most-impacted\/#primaryimage"},"thumbnailUrl":"https:\/\/trak.in\/stories\/wp-content\/uploads\/2025\/09\/Malvika-3-1.jpeg","datePublished":"2025-09-27T03:04:47+00:00","dateModified":"2025-09-27T03:05:54+00:00","author":{"@id":"https:\/\/trak.in\/stories\/#\/schema\/person\/5092a7d2906e3f3c819643435477c2a7"},"breadcrumb":{"@id":"https:\/\/trak.in\/stories\/27-lakh-bank-transfer-records-exposed-sbi-aye-finance-most-impacted\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/trak.in\/stories\/27-lakh-bank-transfer-records-exposed-sbi-aye-finance-most-impacted\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/trak.in\/stories\/27-lakh-bank-transfer-records-exposed-sbi-aye-finance-most-impacted\/#primaryimage","url":"https:\/\/trak.in\/stories\/wp-content\/uploads\/2025\/09\/Malvika-3-1.jpeg","contentUrl":"https:\/\/trak.in\/stories\/wp-content\/uploads\/2025\/09\/Malvika-3-1.jpeg","width":1000,"height":465},{"@type":"BreadcrumbList","@id":"https:\/\/trak.in\/stories\/27-lakh-bank-transfer-records-exposed-sbi-aye-finance-most-impacted\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/trak.in\/stories\/"},{"@type":"ListItem","position":2,"name":"27 Lakh Bank Transfer Records Exposed: SBI, Aye Finance Most Impacted"}]},{"@type":"WebSite","@id":"https:\/\/trak.in\/stories\/#website","url":"https:\/\/trak.in\/stories\/","name":"Trak.in - Indian Business of Tech, Mobile &amp; Startups","description":"Trak.in is a popular Indian Business, Technology, Mobile &amp; Startup blog featuring trending News, views and analytical take on Technology, Business, Finance, Telecom, Mobile, startups &amp; Social Media Space","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/trak.in\/stories\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/trak.in\/stories\/#\/schema\/person\/5092a7d2906e3f3c819643435477c2a7","name":"Mohul Ghosh","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/trak.in\/stories\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/66c129d83dd3f325a3b550eb1aa16891173ddfc4686361424206cd9a01311c89?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/66c129d83dd3f325a3b550eb1aa16891173ddfc4686361424206cd9a01311c89?s=96&d=mm&r=g","caption":"Mohul Ghosh"},"url":"https:\/\/trak.in\/stories\/author\/mohul-ghosh\/"}]}},"jetpack_featured_media_url":"https:\/\/trak.in\/stories\/wp-content\/uploads\/2025\/09\/Malvika-3-1.jpeg","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/trak.in\/stories\/wp-json\/wp\/v2\/posts\/1300720","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/trak.in\/stories\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/trak.in\/stories\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/trak.in\/stories\/wp-json\/wp\/v2\/users\/30"}],"replies":[{"embeddable":true,"href":"https:\/\/trak.in\/stories\/wp-json\/wp\/v2\/comments?post=1300720"}],"version-history":[{"count":1,"href":"https:\/\/trak.in\/stories\/wp-json\/wp\/v2\/posts\/1300720\/revisions"}],"predecessor-version":[{"id":1300730,"href":"https:\/\/trak.in\/stories\/wp-json\/wp\/v2\/posts\/1300720\/revisions\/1300730"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/trak.in\/stories\/wp-json\/wp\/v2\/media\/1300729"}],"wp:attachment":[{"href":"https:\/\/trak.in\/stories\/wp-json\/wp\/v2\/media?parent=1300720"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/trak.in\/stories\/wp-json\/wp\/v2\/categories?post=1300720"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/trak.in\/stories\/wp-json\/wp\/v2\/tags?post=1300720"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}