- FatakPay, an Indian loan company, was found storing sensitive data in an unprotected S3 bucket
- The data included people’s names, addresses, IDs, and more
- The company has since locked the database down
Instant loan company FatakPay kept sensitive data on millions of its users exposed on the internet, for an unknown period of time to anyone who knew where to look.
In mid-September 2024, security researchers from Cybernews discovered a misconfigured Amazon AWS S3 bucket containing more than 27 million files filled with sensitive information.
The data found in the bucket includes people’s full names, postal addresses, email addresses, phone numbers, copies of national IDs, loan agreements, account statements, filled-in loan applications, user selfies for verification, PAN (a PIN number issued by the Indian Income Tax Department), Aadhar (a PIN number issued by the Unique Identification Authority of India), and credit score reports.
Closing the archive
After a few attempts, the researchers managed to get in touch with FatakPay, which then closed the bucket, but has not yet released an official statement regarding the discovery.
FatakPay is a digital payment and micro-lending platform in India that provides instant credit solutions to users for small-ticket transactions. At press time, its Google Play Store page shows 1M+ downloads, but the exact number of active users is not publicly available.
Misconfigured databases remain one of the key causes of data leaks. Some researchers warned that many organizations don’t fully understand the shared responsibility model of most cloud hosting providers, and that they believe it is the service provider’s job to keep the data secure.
As a result, researchers often stumble upon large databases full of information that crooks could use for identity theft, phishing, social engineering, wire fraud, and more.
Recently, a Mexican fintech startup was found holding a large database full of sensitive customer data wide open on the internet. The company, called Kapital, held data on 1.6 million Mexicans, including voter IDs and selfies.
You might also like
- Top Mexican fintech firm leaks details on 1.6 million customers
- Here’s a list of the best antivirus tools on offer
- These are the best endpoint protection tools right now
This articles is written by : Fady Askharoun Samy Askharoun
All Rights Reserved to Amznusa www.amznusa.com
Why Amznusa?
AMZNUSA is a dynamic website that focuses on three primary categories: Technology, e-commerce and cryptocurrency news. It provides users with the latest updates and insights into online retail trends and the rapidly evolving world of digital currencies, helping visitors stay informed about both markets.