Cyber Security News

Brokerage Firm Upstox Exposes 2.5 Million Customers Sensitive Information

Upstox suffers a security breach, resulting in the exposure of 2.5 million users’ sensitive information online from unsecured AWS S3 Bucket.

The exposed details include names, email addresses, dates of birth, bank account information, and KYC documents from the company’s server.

Security researcher Rajshekhar Rajaharia disclosed the breach first on April 11th, it was not sure when the breach occurred.

Reacting to the story, Upstox said that “we have upgraded our security systems manifold recently, on the recommendations of a global cyber-security firm. We brought in the expertise of this globally renowned firm after we received emails claiming unauthorized access into our database.”

Also the company added that “hese claims suggested that some contact data and KYC details may have been compromised from third-party data-warehouse systems.”

The company confirmed that customers’ funds are safe and “can only be moved to your linked bank accounts”.

It is recommended to have a strong and unique passwords and carefully watch out for OTP request.

The Upstox breach followed by India-based digital wallet service MobiKwik that exposes 120 million users, 3 million merchants, and 300+ billers.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity and hacking news updates.

Guru Baran

Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Recent Posts

SecAI Debuts at RSA 2025, Redefining Threat Investigation with AI

By fusing agentic AI and contextual threat intelligence, SecAI transforms investigation from a bottleneck into…

1 hour ago

How Healthcare Providers Investigate And Prevent Cyber Attacks: Real-world Examples

According to IBM Security annual research, "Cost of a Data Breach Report 2024", an average…

2 hours ago

NVIDIA Riva Vulnerabilities Exposes Enable Authorized Access to Cloud Environments

A critical security flaw in NVIDIA's Riva framework, an AI-powered speech and translation service, has…

3 hours ago

CISA Adds Broadcom Brocade Fabric OS Vulnerability to Known Exploited Vulnerabilities Catalog

CISA officially added a significant security flaw affecting Broadcom’s Brocade Fabric OS to its authoritative…

3 hours ago

AirPlay Zero-Click RCE Vulnerability Enables Remote Device Takeover via Wi-Fi

A critical vulnerability in Apple’s AirPlay protocol, dubbed AirBorne, has exposed over 2.35 billion active…

3 hours ago

Google Chrome Vulnerability Let Attackers Escape Payload from Sandbox – Technical Details Disclosed

A critical vulnerability in Google Chrome has recently been discovered that allows malicious actors to…

4 hours ago