Skip to main content

This widely-used instant loan app leaks nearly 30 million files of user data

Web Hosting & Remote IT Support

  • FatakPay, an Indian loan company, was found storing sensitive data in an unprotected S3 bucket
  • The data included people's names, addresses, IDs, and more
  • The company has since locked the database down

Instant loan company FatakPay kept sensitive data on millions of its users exposed on the internet, for an unknown period of time to anyone who knew where to look.

In mid-September 2024, security researchers from Cybernews discovered a misconfigured Amazon AWS S3 bucket containing more than 27 million files filled with sensitive information.

The data found in the bucket includes people’s full names, postal addresses, email addresses, phone numbers, copies of national IDs, loan agreements, account statements, filled-in loan applications, user selfies for verification, PAN (a PIN number issued by the Indian Income Tax Department), Aadhar (a PIN number issued by the Unique Identification Authority of India), and credit score reports.

Closing the archive

After a few attempts, the researchers managed to get in touch with FatakPay, which then closed the bucket, but has not yet released an official statement regarding the discovery.

FatakPay is a digital payment and micro-lending platform in India that provides instant credit solutions to users for small-ticket transactions. At press time, its Google Play Store page shows 1M+ downloads, but the exact number of active users is not publicly available.

Misconfigured databases remain one of the key causes of data leaks. Some researchers warned that many organizations don’t fully understand the shared responsibility model of most cloud hosting providers, and that they believe it is the service provider’s job to keep the data secure.

As a result, researchers often stumble upon large databases full of information that crooks could use for identity theft, phishing, social engineering, wire fraud, and more.

Recently, a Mexican fintech startup was found holding a large database full of sensitive customer data wide open on the internet. The company, called Kapital, held data on 1.6 million Mexicans, including voter IDs and selfies.

You might also like



via Hosting & Support

Comments

Popular posts from this blog

Hacking Huawei Modems

Report: Android's desktop mode might allow future tablets to double as computers

Web Hosting & Remote IT Support Back in April , evidence surfaced online revealing that Google was working on improving Android's desktop mode. Early demos show it’ll be more user-friendly than before by having movable windows, although it still lacks vital features. Since then, we haven’t heard much about the project until recently, when it popped up again in the “latest Android 15 Beta 4.1 release”. Android expert Mishaal Rahman discovered that Android’s feature may work on a tablet – provided it has a big enough display. In the build, he states that if you go to the device’s 'Recents' view and open the dropdown menu for an app, you will see a new button called “Desktop.” Tapping said button causes whatever app you were on to turn into a free-floating window. From here on, it behaves similarly to a browser on Samsung's New DeX system. The app can be minimized, maximized, attached to the side, or connected to another window. Down at the bottom is a taskbar...