Friday , May 9 2025

Multinational bank leaks passports and credit card numbers

ICICI Bank leaked millions of records with sensitive data, including financial information and personal documents of the bank’s clients.

  • ICICI Bank, an Indian multinational valued at more than $76 billion, has more than 5,000 branches across India and is present in at least another 15 countries worldwide.
  • A misconfiguration of the bank systems exposed millions of records with sensitive data.
  • Among the leaked data were bank account details, bank statements, credit card numbers, full names, dates of birth, home addresses, phone numbers, emails, personal identification documents, and employees’ and candidates’ CVs.
  • Cybernews contacted ICICI Bank and CERT-IN, and the company fixed the issue.

In 2022, the ICICI Bank’s resources were named a “critical information infrastructure” by the Indian government – any harm to it can impact national security. However, despite the critical status of bank infrastructure on the national level, the security of crucial data was not ensured.

Qilin Ransomware topped April 2025 with 45+ data leak disclosures

The cyber threat landscape is rapidly changing, with a notable increase in ransomware activity in April 2025, driven by the...
Read More
Qilin Ransomware topped April 2025 with 45+ data leak disclosures

SonicWall Patches 3 Flaws in SMA 100 Devices

SonicWall has released patches for three security flaws in SMA 100 Secure Mobile Access appliances that could allow remote code...
Read More
SonicWall Patches 3 Flaws in SMA 100 Devices

Top Ransomware Actively Attacking Financial Sector: 406 Incidents Disclosed

From April 2024 to April 2025, Flashpoint analysts noted that the financial sector was a major target for threat actors,...
Read More
Top Ransomware Actively Attacking Financial Sector: 406 Incidents Disclosed

Critical (CVSS 10) Flaw in Cisco IOS XE WLCs Allows RRA

Cisco has issued a security advisory for a critical vulnerability in its IOS XE Software for Wireless LAN Controllers (WLCs)....
Read More
Critical (CVSS 10) Flaw in Cisco IOS XE WLCs Allows RRA

CVE-2025-29824
Play Ransomware Exploited Windows CVE-2025-29824 as Zero-Day

Attackers linked to the Play ransomware operation deployed a zero-day privilege escalation exploit during an attempted attack against an organization...
Read More
CVE-2025-29824  Play Ransomware Exploited Windows CVE-2025-29824 as Zero-Day

Hacker exploited Samsung MagicINFO 9 Server RCE flaw

Hackers are exploiting an unauthenticated remote code execution vulnerability in the Samsung MagicINFO 9 Server to take control of devices...
Read More
Hacker exploited Samsung MagicINFO 9 Server RCE flaw

CISA adds Langflow flaw to its KEV catalog

CISA added the Langflow vulnerability, CVE-2025-3248 (CVSS score 9.8), to its Known Exploited Vulnerabilities catalog. Langflow is a popular tool...
Read More
CISA adds Langflow flaw to its KEV catalog

Google Fixes Android Flaw (CVE-2025-27363) Exploited by Attackers

Google has released its monthly Android security updates, addressing 46 vulnerabilities, including one that has been actively exploited. CVE-2025-27363 (CVSS...
Read More
Google Fixes Android Flaw (CVE-2025-27363) Exploited by Attackers

UAP hosted “UAP Cyber Siege 2025”, A national level cybersecurity competition

The Cyber Security Club, representing the Department of Computer Science and Engineering at the University of Asia Pacific (UAP), has...
Read More
UAP hosted “UAP Cyber Siege 2025”, A national level cybersecurity competition

xAI Dev Leaks API Key for Private SpaceX, Tesla & Tweeter

A major security issue happened at Elon Musk’s AI company, xAI, when a developer accidentally posted a private API key...
Read More
xAI Dev Leaks API Key for Private SpaceX, Tesla & Tweeter

During the recent investigation, the Cybernews research team discovered that the bank leaked the sensitive data due to the misconfiguration of their systems.

If malicious actors accessed the exposed data, the company could have faced devastating consequences and put their clients at risk, as financial services are the main target for cybercriminals.

Screenshot of leaked passport
Screenshot of leaked passport

Leaked personal data

On February 1, the Cybernews research team discovered a misconfigured and publicly accessible cloud storage – Digital Ocean bucket – with over 3.6 million files belonging to ICICI Bank. Files exposed sensitive data of the bank and its clients.

Among the leaked clients’ data, there were bank account details, credit card numbers, full names, dates of birth, home addresses, phone numbers, and emails.

Screenshot of leaked bank statement
Screenshot of leaked bank statement

The bucket also stored files that revealed clients’ passports, IDs, and Indian PANs – Indian taxpayer identification numbers. Bank statements and filled-in know-your-customer (KYC) forms were also leaked.

The leak affected the bank’s staff as well, as CVs of current employees and job candidates were observed in the storage.

Company’s response

Cybernews reached out both to the bank and Indian Computer Emergency Response Team (CERT-IN), and the issue was fixed.

Cybernews researchers assert that access to the Digital Ocean bucket belonging to ICICI Bank was fully restricted on March 30.

We’ve also attempted to obtain an official comment from the bank’s communication team.

“Thanks for your email. With regards to it, we do not know which incident you are referring to,” the email reads.

The company recommended contacting the Corporate Communications Team. Unfortunately, Cybernews journalist’s email was rejected, and, at the time of writing, we’ve received no official response from the bank.

ICICI Bank's response
ICICI Bank’s response

Threat to financial accounts

Finance and insurance are one of the most targeted industries by cybercriminals.

Last year, with a total share of 18% of all cyberattacks, it was the second most targeted industry, following manufacturing.

The numbers are not surprising, as financial companies hold a treasure trove of sensitive and valuable data and financial assets, making them attractive targets.

“The impact of the discovered ICICI leak is estimated to be severe, as the volume of personal data leakage is significant,” said Cybernews researchers. “Such sensitive information could undermine ICICI bank’s reputation and may uncover details of the bank’s internal processes as well as jeopardize the safety and security of its clients and employees and their data.”

Screenshot of leaked filled-in KYC form
Screenshot of leaked filled-in KYC form

According to researchers, threat actors could use leaked data to commit identity theft and fraud. “For example, cybercriminals could use the stolen credentials and personal data to open accounts in the names of individuals without them being aware. Employees, businesses, and individuals whose data were exposed could be at risk of spear phishing campaigns,” added researchers.

The banking sector is especially vulnerable to phishing attacks, as malicious actors often go after logins to online banking platforms, credit card credentials, and bank account numbers.

Malicious actors could use leaked data to construct a successful phishing attack to gain access to bank accounts, make transfers, and perpetrate credit-card fraud.

“Another risk is the data being sold on the dark web, and ICICI Bank risking to be a victim of ransomware attacks,” added the Cybernews team.

Keep clients informed

To prevent such data leaks, researchers advise always securing cloud storage buckets. The ICICI Bank should mitigate the risk and further damage by notifying its customers of the data leak.

ICICI Bank should provide guidance for customers on identifying and avoiding fraudulent emails, websites, and calls, and urge them to immediately report any suspicious activities to the bank.

Those affected should change their login details and create strong passwords, as attackers could easily guess weak ones due to the vast amount of personally identifiable information (PII) exposed.

Check Also

Quantum Computing Village

India Launches First Quantum Computing Village in Amaravati

India has taken a monumental stride toward next-generation technology by initiating its first Quantum Computing …

Leave a Reply

Your email address will not be published. Required fields are marked *