Policybazaar system vulnerabilities exposed customers’ personal details: Report


PTI, Aug 10, 2022, 6:30 PM IST

New Delhi: Vulnerabilities in the system of online insurance broker Policybazaar led to exposure of personal details of lakhs of its customers, including defence personnel, a cyber security research firm claimed on Wednesday.

CyberX9 said Aadhaar and PAN card details as well as addresses and phone numbers of customers were exposed due to the vulnerabilities and that the issue was reported to Policybazaar on July 18.

On July 24, Policybazaar informed stock exchanges that it had noticed the vulnerabilities on July 19 and that no significant customer data was exposed.

When contacted on Wednesday, a Policybazaar spokesperson referred to its filing to the stock exchanges made on July 24 and said the identified vulnerabilities have been duly fixed as confirmed by an external advisor.

”A thorough forensic audit of the incident has been initiated with external advisors. The incident was covered by the media. We have nothing further to add,” the spokesperson said in a statement.

The online broker’s parent PB Fintech is listed on the stock exchanges.

In its report, CyberX9 claimed Policybazaar exposed all confidential and sensitive personal information, including that of Aadhaar, PAN card and Passport, of millions of the customers.

It also claimed that the vulnerabilities in Policybazaar’s system potentially exposed data of 56.4 million people who have transacted on the platform.

”The information exposed to the whole internet included but not limited to, customer’s full name, date of birth, complete residential address, email address, mobile number, policy details, including nominee details, copies of user’s bank account statements, income tax returns documents, Passport, Aadhaar card, PAN card, and so on,” it said.

In case of the defence personnel, information such as designation, location of their posting and activities they are engaged in were exposed, the report claimed.

After informing Policybazaar about the vulnerabilities on July 18, CyberX9 reported the incident to cyber security watchdog CERT-IN on July 24.

”CERT-In confirmed to us on July 25 that Policybazaar has now admitted and fixed the reported vulnerabilities and asked us to retest if the vulnerabilities were fixed,” the report said.

CyberX9 said it also submitted the report to National Cyber Security Coordinator Rajesh Pant who promised to initiate action against Policybazaar.

”Rajesh Pant promptly reverted back to us after going through the information we shared, they thanked us for the information and informed us that they shall initiate action against Policybazaar,” the report said.

An email query sent to Pant on the issue remained unanswered.

”At the end of our analysis, we came to the conclusion that there is high potential that Policybazaar could be having these vulnerabilities as intentional backdoor vulnerabilities in order to potentially allow access to the Chinese government to sensitive data of Indian nationals and particularly defense personnel,” CyberX9 alleged.

Udayavani is now on Telegram. Click here to join our channel and stay updated with the latest news.

Top News

Actress Kasthuri released from jail, says ‘I thank those who made me raging storm’

Kidnapped for ransom in 1998, 26/11 survivor Gautam Adani faces biggest trial

100 engineering colleges in Karnataka to be ‘adopted’ by corporates by next year: IT Minister Kharge

Siddaramaiah defends BPL ration card cancellation, says only ineligible beneficiaries affected

China announces new policy measures to protect its exports from Trump’s new tariff threat

Renovated Medical Oncology OPD and Chemotherapy Day Care Centre inaugurated at Kasturba Hospital, Manipal

Karnataka Health Minister justifies revision of user fees in state-run hospitals

Related Articles More

Kidnapped for ransom in 1998, 26/11 survivor Gautam Adani faces biggest trial

Gautam Adani charged in US with USD 250 mn bribery, fraud

India’s GDP growth likely to slip at 6.5 pc, maintains 7 pc estimate for FY25: Icra

RBI cautions public about ‘deepfake’ video of governor being circulated on social media

We disagree with decision, plan to appeal: Meta on CCI imposing Rs 213-cr penalty

MUST WATCH

Christmas Cake Fruit Mixing

DK Shivakumar

Rose Cultivation

Geethotsava

Naxal Operation


Latest Additions

Siddaramaiah says confident of winning all three bypolls in Karnataka

Hop on! IT Minister Priyank Kharge checks out Uber Shuttle at Bengaluru Tech Summit

Actress Kasthuri released from jail, says ‘I thank those who made me raging storm’

Kidnapped for ransom in 1998, 26/11 survivor Gautam Adani faces biggest trial

AIMPLB to hold its annual general sessions in Bengaluru from November 23

Thanks for visiting Udayavani

You seem to have an Ad Blocker on.
To continue reading, please turn it off or whitelist Udayavani.