Skip to main content

This widely-used instant loan app leaks nearly 30 million files of user data

Web Hosting & Remote IT Support

  • FatakPay, an Indian loan company, was found storing sensitive data in an unprotected S3 bucket
  • The data included people's names, addresses, IDs, and more
  • The company has since locked the database down

Instant loan company FatakPay kept sensitive data on millions of its users exposed on the internet, for an unknown period of time to anyone who knew where to look.

In mid-September 2024, security researchers from Cybernews discovered a misconfigured Amazon AWS S3 bucket containing more than 27 million files filled with sensitive information.

The data found in the bucket includes people’s full names, postal addresses, email addresses, phone numbers, copies of national IDs, loan agreements, account statements, filled-in loan applications, user selfies for verification, PAN (a PIN number issued by the Indian Income Tax Department), Aadhar (a PIN number issued by the Unique Identification Authority of India), and credit score reports.

Closing the archive

After a few attempts, the researchers managed to get in touch with FatakPay, which then closed the bucket, but has not yet released an official statement regarding the discovery.

FatakPay is a digital payment and micro-lending platform in India that provides instant credit solutions to users for small-ticket transactions. At press time, its Google Play Store page shows 1M+ downloads, but the exact number of active users is not publicly available.

Misconfigured databases remain one of the key causes of data leaks. Some researchers warned that many organizations don’t fully understand the shared responsibility model of most cloud hosting providers, and that they believe it is the service provider’s job to keep the data secure.

As a result, researchers often stumble upon large databases full of information that crooks could use for identity theft, phishing, social engineering, wire fraud, and more.

Recently, a Mexican fintech startup was found holding a large database full of sensitive customer data wide open on the internet. The company, called Kapital, held data on 1.6 million Mexicans, including voter IDs and selfies.

You might also like



via Hosting & Support

Comments

Popular posts from this blog

Microsoft, Google, and Meta have borrowed EV tech for the next big thing in data centers: 1MW watercooled racks

Web Hosting & Remote IT Support Liquid cooling isn't optional anymore, it's the only way to survive AI's thermal onslaught The jump to 400VDC borrows heavily from electric vehicle supply chains and design logic Google’s TPU supercomputers now run at gigawatt scale with 99.999% uptime As demand for artificial intelligence workloads intensifies, the physical infrastructure of data centers is undergoing rapid and radical transformation. The likes of Google, Microsoft, and Meta are now drawing on technologies initially developed for electric vehicles (EVs), particularly 400VDC systems, to address the dual challenges of high-density power delivery and thermal management. The emerging vision is of data center racks capable of delivering up to 1 megawatt of power, paired with liquid cooling systems engineered to manage the resulting heat. Borrowing EV technology for data center evolution The shift to 400VDC power distribution marks a decisive break from legacy sy...

Google’s AI Mode can explain what you’re seeing even if you can’t

Web Hosting & Remote IT Support Google’s AI Mode now lets users upload images and photos to go with text queries The feature combines Google Gemini and Lens AI Mode can understand entire scenes, not just objects Google is adding a new dimension to its experimental AI Mode by connecting Google Lens's visual abilities with Gemini . AI Mode is a part of Google Search that can break down complex topics, compare options, and suggest follow-ups. Now, that search includes uploaded images and photos taken on your smartphone. The result is a way to search through images the way you would text but with much more complex and detailed answers than just putting a picture into reverse image search. You can literally snap a photo of a weird-looking kitchen tool and ask, “What is this, and how do I use it?” and get a helpful answer, complete with shopping links and YouTube demos. AI Eyes If you take a picture of a bookshelf, a plate of food, or the chaotic interior of your junk...