Security News

Cybersecurity news aggregator

HIGH Attacks SC Media

Indian bank domain registrar allegedly leaks sensitive data

A security researcher alleges that the IDRBT's .bank.in domain registration portal exposed over 33 unauthenticated API endpoints, potentially allowing unauthorized access to sensitive employee data including bcrypt password hashes and contact information. The portal reportedly operated with these flaws for 13 months, and many registered domains also lacked DNSSEC and DMARC, increasing risks of phishing and DNS spoofing. While IDRBT has reportedly addressed the vulnerabilities, the exposure undermined the RBI's security initiative for the banking namespace.
Read Full Article →

Data Security Indian bank domain registrar allegedly leaks sensitive data June 30, 2026 Share By SC Staff (Adobe Stock) The Reserve Bank of India's initiative to enhance online banking security through the .bank.in subdomain has been marred by allegations of a significant data leak. A security researcher claims that the designated registrar for these domains, the Institute for Development and Research in Banking Technology (IDRBT), failed to secure its registration portal, potentially exposing sensitive information of bank employees and compromising the very security measures intended to protect customers, as reported by The Register. A security researcher, operating under the pseudonym "Srikanth L" and affiliated with CashlessConsumer, has alleged that the IDRBT's Domain Registration Portal, the exclusive registrar for India's .bank.in namespace, exposed over 33 unauthenticated API endpoints. This alleged vulnerability could have allowed unauthorized access to bcrypt password hashes, mobile numbers, email addresses, login IPs, and device fingerprints of 5,576 bank employees. The researcher also found that many Indian banks' .bank.in domains lack crucial security protocols like DNSSEC and DMARC, and some websites are hosted on shared servers internationally. The portal reportedly operated with these security flaws for 13 months without a proper audit. While IDRBT has since reportedly addressed the vulnerabilities, the initial exposure could have potentially facilitated phishing and DNS spoofing attacks, undermining the RBI's efforts to combat fraud. Source: The Register SC Staff Related Encryption Researchers discover new class of weak RSA keys in the wild SC Staff June 29, 2026 The identified weak keys exhibit patterns of regularly spaced blocks of zeros. Data Security Trump signs executive order to accelerate US quantum computing strategy SC Staff June 29, 2026 Trump order accelerates U.S. quantum strategy, boosting post-quantum security. Data Security Attackers create deceptive OpenAI tenants to steal company data SC Staff June 29, 2026 The campaign, dubbed "Poisoned Tenant" and discovered by Push Security, involves attackers creating fake OpenAI organizations using Gmail addresses but sending invitations from OpenAI's legitimate notification system. Related Events Cybercast Beyond the Hype: The Cybersecurity Trends CISOs are Keeping an Eye on in 2026 On-Demand Event Cybercast Beyond the data perimeter: Why next-generation DSPM is the foundation for modern data security On-Demand Event Virtual Conference Securing the Future of Finance: Strategies to Counter Modern Cyber Threats On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Bit Block Cipher Ciphertext Cryptographic Algorithm or Hash Cyclic Redundancy Check (CRC) Data Aggregation Data Encryption Standard (DES) Decryption Digital Signature Digital Signature Algorithm (DSA) You can skip this ad in 5 seconds

Share this article