Home » Security News » CDSL breach exposes 44 million investors’ da...

CDSL breach exposes 44 million investors’ data

CDSL breach exposes 44 million investors’ data
Deepanker Verma November 8, 2021 Security

Add Techlomedia as a preferred source on Google. Preferred Source

A vulnerability in CDSL Ventures Limited, a subsidiary of Central Depository Services, has exposed the personal and financial data of over 43.9 million Indian investors online. This data was exposed twice in a span of just 10 days.

A team of cybersecurity experts reported this vulnerability to CERT-In and NCIIPC on October 19. The organization took a week to fix the vulnerability.

Researchers at CyberX9 found a security vulnerability in CDSL’s KYC and reported it. After CDSL developers fixed the issue, researchers again discovered a comprehensive bypass for their solution and managed to get access to data. The data includes personal information such as full name, PAN No, gender, marital status, father/full spouse’s name, date of birth, nationality, residential address, permanent address, contact number, email address, and occupation. Financial data includes annual income tax return date, net worth, Demat account number, broker name, and CDSL Client ID.

“Both times data of people being exposed was of those who did their market securities KYC…Similar to last time, the discovered issue was an authorization vulnerability in a public CDSL’s KYC API, leading to exposing the massive amount of sensitive data to the whole internet,” CyberX9 reported.

Researchers claim that the vulnerability wasn’t highly complex to discover. That means the case was sheer negligence by CDSL. CDSL also took a week to fix the vulnerability that shouldn’t take more than 2 hours. Unlike most companies, CDSL doesn’t even have a way to contact their security team to responsibly report security vulnerabilities.

The exposed data can be used to perform phishing attacks on investors. Hackers can impersonate brokers, banks, and companies to dupe them. There could also be income tax refund scams and extortion calls.

Follow Techlomedia on Google News to stay updated. Follow on Google News

Affiliate Disclosure:

This article may contain affiliate links. We may earn a commission on purchases made through these links at no extra cost to you.

Deepanker Verma

About the Author: Deepanker Verma

Deepanker Verma is the Founder and Editor-in-Chief of TechloMedia. He holds Engineering degree in Computer Science and has over 15 years of experience in the technology sector. Deepanker bridges the gap between complex engineering and consumer electronics. He is also a a known Security Researcher acknowledged by global giants including Apple, Microsoft, and eBay. He uses his technical background to rigorously test gadgets, focusing on performance, security, and long-term value.

Related Posts

Stay Updated with Techlomedia

Join our newsletter to receive the latest tech news, reviews, and guides directly in your inbox.