Policybazaar exposes millions of Indian Customers’ data
By MYBRANDBOOK
Research firm CyberX9 has claimed that Chinese Investor-Backed Policybazaar has allegedly exposed sensitive and confidential personal, health, and financial data of around 56.4 million of its customers including defense personnels and potentially compromises national security.
A Policybazaar spokesperson said the identified vulnerabilities have been duly fixed as confirmed by an external advisor. “A thorough forensic audit of the incident has been initiated with external advisors. The incident was covered by the media. We have nothing further to add,” the spokesperson said.
The information exposed includes customers’ photo, full name, date of birth, complete residential address, email address, mobile number, credit report, PAN number, policy details including nominee details, family members’ policies details, bank account statements, income tax returns, Passport, immigration visa, records of country entry and exit, Aadhaar card (both sides), driving license, health records, payslips.
For Indian defense personnels, the data was being exposed along with that data of a “Defense questioner” that Policybazaar takes from people working in Indian defense forces, including the questionnaire replies by defense personnels who bought policy from Policybazaar.
Apart from the above mentioned data, details of which specific branch of Indian defense forces someone is in like Indian Army, Navy, Air force, and even specifics if someone is in one of the Indian special forces like SPG, Black Cat commando, CoBRA, Anti Terrorist Squad, current rank and designation in that defense force, current location of posting, details if someone is engaged in any hazardous activities, e.g. aviation, diving, parachuting, bomb disposal or special service groups, and length of service in those roles, details if someone in Indian defense is currently serving in or is under orders to proceed to any troubled area, or around border areas of India, details of someone handling weapons or explosives were also leaked.
After informing Policybazaar about the vulnerabilities, CyberX9 reported the incident to cyber security watchdog CERT-In. National security agencies have initiated action against Policybazaar.
Nazara and ONDC set to transform in-game monetization with ‘
Nazara Technologies has teamed up with the Open Network for Digital Comme...
Jio Platforms and NICSI to offer cloud services to government
In a collaborative initiative, the National Informatics Centre Services In...
BSNL awards ₹5,000 Cr Project to RVNL-Led Consortium
A syndicate led by Rail Vikas Nigam Limited (abbreviated as RVNL), along wi...
Pinterest tracks users without consent, alleges complaint
A recent complaint alleges that Pinterest, the popular image-sharing platf...
DRUVA SOFTWARE PVT. LTD.
ZOHO CORPORATION PVT. LTD.
CENTRE FOR DEVELOPMENT OF TELEMATICS (C-DOT)
QUICK HEAL TECHNOLOGIES PVT. LTD.
ICONS OF INDIA : SANDIP PATEL
Sandip Patel is the Managing Director for IBM India & South Asia regio...
ICONS OF INDIA : SRIDHAR VEMBU
Sridhar Vembu is the chief executive officer (CEO) of Zoho Corporation...
Icons Of India : Debjani Ghosh
Debjani Ghosh is the President of the National Association of Software...
NIC - National Informatics Centre
NIC serves as the primary IT solutions provider for the government of ...
NSE - National Stock Exchange
NSE is the leading stock exchange in India....
C-DOT - Center of Development of Telematics
India’s premier research and development center focused on telecommu...
Indian Tech Talent Excelling The Tech World - Sanjay Mehrotra, CEO- Micron Technology
Sanjay Mehrotra, the President and CEO of Micron Technology, is at the...
Indian Tech Talent Excelling The Tech World - Aman Bhutani, CEO, GoDaddy
Aman Bhutani, the self-taught techie and CEO of GoDaddy, oversees a co...
Indian Tech Talent Excelling The Tech World - Anirudh Devgan , President, Cadence Design
Anirudh Devgan, the Global President and CEO of Cadence Design Systems...