Monday , August 3 2026

Multinational bank leaks passports and credit card numbers

ICICI Bank leaked millions of records with sensitive data, including financial information and personal documents of the bank’s clients.

  • ICICI Bank, an Indian multinational valued at more than $76 billion, has more than 5,000 branches across India and is present in at least another 15 countries worldwide.
  • A misconfiguration of the bank systems exposed millions of records with sensitive data.
  • Among the leaked data were bank account details, bank statements, credit card numbers, full names, dates of birth, home addresses, phone numbers, emails, personal identification documents, and employees’ and candidates’ CVs.
  • Cybernews contacted ICICI Bank and CERT-IN, and the company fixed the issue.

In 2022, the ICICI Bank’s resources were named a “critical information infrastructure” by the Indian government – any harm to it can impact national security. However, despite the critical status of bank infrastructure on the national level, the security of crucial data was not ensured.

CISA alerts to cyberattacks affecting U.S. water utilities

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warns of a big rise in attacks on internet-connected programmable logic controllers...
Read More
CISA alerts to cyberattacks affecting U.S. water utilities

“CyberStrike” AI-Driven Security Platform for Automated Testing

A new open-source project named CyberStrike aims to be the first AI tool made for offensive security. It can turn...
Read More
“CyberStrike” AI-Driven Security Platform for Automated Testing

AIDCQ Propose to invest $2 billion in AI data center in Bangladesh

Many countries are now showing interest to invest in the data center industry in Banglades especially in AI data centers....
Read More
AIDCQ Propose to invest $2 billion in AI data center in Bangladesh

NVIDIA BlueField Flaw Enables Code Execution Attacks

NVIDIA has revealed a big flaw with its BlueField DPUs and ConnectX networking systems. This issue could let attackers run...
Read More
NVIDIA BlueField Flaw Enables Code Execution Attacks

Massive customer data from India’s Bank of Baroda surfaced online

India's leading state-owned lender Bank of Baroda acknowledged Monday a security incident after reports that approximately 1 terabyte of customer...
Read More
Massive customer data from India’s Bank of Baroda surfaced online

Active Exploits Hit Fortinet, Arista: AI Discovered Linux Kernel Zero-Day

CISA has put the Fortinet FortiOS vulnerability CVE-2025-68686 in its list of known exploited flaws after ongoing attacks. The flaw...
Read More
Active Exploits Hit Fortinet, Arista: AI Discovered Linux Kernel Zero-Day

Sam Altman Claims AI “singularity” has arrived, Where Systems Improve by Themselves

OpenAI's CEO Sam Altman says that AI has reached a big milestone. The technology can now make itself better, leading...
Read More
Sam Altman Claims AI “singularity” has arrived, Where Systems Improve by Themselves

Shinyhunters claimed and set deadline to publish E&Y data

ShinyHunters has publicly claimed responsibility for the Ernst & Young (EY) data breach. The group posted a message on their...
Read More
Shinyhunters claimed and set deadline to publish E&Y data

Microsoft, NVIDIA and CrowdStrike Initiate Alliance for Open-Source AI Security

Nvidia and over 30 tech firms started a group on Monday to create open-source AI tools for protecting against cyber...
Read More
Microsoft, NVIDIA and CrowdStrike Initiate Alliance for Open-Source AI Security

Google Search Results Reportedly Show Claude AI Shared Chats

Claude's share links from Anthropic showed up in public search results. This raised new privacy worries for users who shared...
Read More
Google Search Results Reportedly Show Claude AI Shared Chats

During the recent investigation, the Cybernews research team discovered that the bank leaked the sensitive data due to the misconfiguration of their systems.

If malicious actors accessed the exposed data, the company could have faced devastating consequences and put their clients at risk, as financial services are the main target for cybercriminals.

Screenshot of leaked passport
Screenshot of leaked passport

Leaked personal data

On February 1, the Cybernews research team discovered a misconfigured and publicly accessible cloud storage – Digital Ocean bucket – with over 3.6 million files belonging to ICICI Bank. Files exposed sensitive data of the bank and its clients.

Among the leaked clients’ data, there were bank account details, credit card numbers, full names, dates of birth, home addresses, phone numbers, and emails.

Screenshot of leaked bank statement
Screenshot of leaked bank statement

The bucket also stored files that revealed clients’ passports, IDs, and Indian PANs – Indian taxpayer identification numbers. Bank statements and filled-in know-your-customer (KYC) forms were also leaked.

The leak affected the bank’s staff as well, as CVs of current employees and job candidates were observed in the storage.

Company’s response

Cybernews reached out both to the bank and Indian Computer Emergency Response Team (CERT-IN), and the issue was fixed.

Cybernews researchers assert that access to the Digital Ocean bucket belonging to ICICI Bank was fully restricted on March 30.

We’ve also attempted to obtain an official comment from the bank’s communication team.

“Thanks for your email. With regards to it, we do not know which incident you are referring to,” the email reads.

The company recommended contacting the Corporate Communications Team. Unfortunately, Cybernews journalist’s email was rejected, and, at the time of writing, we’ve received no official response from the bank.

ICICI Bank's response
ICICI Bank’s response

Threat to financial accounts

Finance and insurance are one of the most targeted industries by cybercriminals.

Last year, with a total share of 18% of all cyberattacks, it was the second most targeted industry, following manufacturing.

The numbers are not surprising, as financial companies hold a treasure trove of sensitive and valuable data and financial assets, making them attractive targets.

“The impact of the discovered ICICI leak is estimated to be severe, as the volume of personal data leakage is significant,” said Cybernews researchers. “Such sensitive information could undermine ICICI bank’s reputation and may uncover details of the bank’s internal processes as well as jeopardize the safety and security of its clients and employees and their data.”

Screenshot of leaked filled-in KYC form
Screenshot of leaked filled-in KYC form

According to researchers, threat actors could use leaked data to commit identity theft and fraud. “For example, cybercriminals could use the stolen credentials and personal data to open accounts in the names of individuals without them being aware. Employees, businesses, and individuals whose data were exposed could be at risk of spear phishing campaigns,” added researchers.

The banking sector is especially vulnerable to phishing attacks, as malicious actors often go after logins to online banking platforms, credit card credentials, and bank account numbers.

Malicious actors could use leaked data to construct a successful phishing attack to gain access to bank accounts, make transfers, and perpetrate credit-card fraud.

“Another risk is the data being sold on the dark web, and ICICI Bank risking to be a victim of ransomware attacks,” added the Cybernews team.

Keep clients informed

To prevent such data leaks, researchers advise always securing cloud storage buckets. The ICICI Bank should mitigate the risk and further damage by notifying its customers of the data leak.

ICICI Bank should provide guidance for customers on identifying and avoiding fraudulent emails, websites, and calls, and urge them to immediately report any suspicious activities to the bank.

Those affected should change their login details and create strong passwords, as attackers could easily guess weak ones due to the vast amount of personally identifiable information (PII) exposed.

Check Also

Claude Security plugin

Anthropic Unveils Claude Security Plugin for Code Flaw Scanning

Anthropic launched the Claude Security plugin in beta. This tool uses AI to find serious …