CRITICAL SEVERITYFinancial

Upstox Data Breach

Upstox Indian Brokerage Platform Breach (2021): Bank Account Numbers, Government ID, Income & Family Member Names Exposed

Indian online brokerage and investment platform.

Verified by ObscureIQ Intelligence

10.0Severity
111KRecords
13Fields
2021Year

ObscureIQ Breach Intelligence Scores
10.0
Breach Risk Index
70
Data Value
10
Market Recency
1559
days
Since Breach

Risk Interpretation

Severe risk of account takeover, investment fraud, phishing, and identity theft. Trading and holdings context can also help attackers prioritize high-value targets.

🎯 Impact & Downstream Threats

The 2021 breach drew sharp public scrutiny in India and contributed to wider regulatory momentum on consumer data protection in the financial services sector. Upstox publicly acknowledged the incident, reset customer passwords, and engaged external incident-response specialists. The company stated that it had also notified Indian authorities. Public reporting did not surface specific regulatory penalties or settlement outcomes tied to the breach, in part because India's modern data-protection la

Primary downstream threats:
  • Credential stuffing against reused passwords across other platforms
  • Financial fraud using exposed financial profile data
  • Identity theft and synthetic identity construction using government-issued IDs
  • SIM swap attacks where phone numbers are present
  • Targeted phishing campaigns using exposed email addresses
  • Doxxing risk from physical address exposure
  • Employment-based social engineering using job and employer data

🔓 Threat Vectors

ACH fraud & unauthorized transfers
Identity verification bypass
Phishing, credential stuffing & account takeover
Family emergency scams & impersonation
Loan fraud & targeted financial scams
Profile enrichment
Identity fraud with official bodies
Occupation-specific phishing
Targeted visa & government scams
Credential stuffing & account takeover
SIM swapping, vishing & SMS phishing
Physical stalking, mail fraud & identity verification
Social engineering context
Romance & family emergency fraud

📋 Breach Intelligence

EntityUpstox
OrganizationPrivate Company • India
Breach Date2021-04-01
HIBP Added2022-01-19
Records~111K (111,000 records)
Attack VectorMisconfiguration
Threat ActorShinyHunters
SourceHave I Been Pwned / ObscureIQ
SensitivityElevated
Breach ID1401.0
StatusConfirmed

📝 Executive Summary

Upstox, one of India's largest online retail brokerage platforms, suffered a data breach in April 2021. Information from the breach circulated on data-trading forums and was indexed by Have I Been Pwned in early 2022. The threat actor responsible has been associated with the ShinyHunters cybercrime collective, which has been linked to a long series of data-theft and extortion campaigns against companies in India and elsewhere.\n\nThe exposed dataset covered approximately 111,000 customer records. Compromised fields formed an unusually deep know-your-customer profile, including names, dates of birth, gender, marital status, nationality, occupation, income levels, family member names, government-issued identification documents, bank account numbers, physical addresses, phone numbers, email addresses, and passwords stored as bcrypt hashes. The dataset also reportedly contained scanned identity documents, bank statements, and cancelled cheques associated with the platform's KYC onboarding process. Bcrypt is a strong password-hashing algorithm, which limits the immediate risk of password recovery, but the surrounding identity, financial, and family data is not similarly protected.\n\nFor affected individuals, the practical risk is severe and durable. The combination of Aadhaar or PAN identifiers with bank account numbers, family member names, and address creates a strong foundation for synthetic identity fraud, fraudulent loan applications, and impersonation at both Indian financial institutions and government services. Family member names create additional risk of family-emergency scams. Income and occupation fields support targeted financial-product fraud. Affected Upstox customers should treat their KYC data as durably exposed, monitor bank and broker accounts closely, and remain alert to unsolicited contact referencing past trading activity, family members, or Aadhaar-related verification.

🏢 About Upstox

Upstox is one of India's largest online retail brokerage platforms, operated by RKSV Securities India Pvt. Ltd. Headquartered in Mumbai and backed by investors including Tiger Global, Ratan Tata, and Kalaari Capital, the platform offers commission-free equity trading, mutual funds, futures and options, and digital onboarding for retail investors. Indian regulatory requirements mean the platform collects an unusually deep set of know-your-customer (KYC) records during account opening, including government-issued identity documents, bank account verifications, income proofs, and family-relationship declarations. The customer base is heavily concentrated in India and skews toward first-time and digitally native retail investors.

Financial institution | Investment and trading services | Brokerage platform | India
Private CompanyIndiaupstox.com

🗂 Why They Hold Your Data

Brokerage platforms collect customer identity, account details, bank-linkage records, trading activity, balances, device metadata, and compliance documentation across investment workflows.

📰 Recent Developments

Upstox has continued to grow rapidly in the Indian retail-investing market in the years since the 2021 incident, supported by the broader expansion of digital trading platforms among Indian retail investors. The company stated at the time that it had reset customer passwords and secured affected systems. Indian regulatory frameworks have since matured significantly, with the Digital Personal Data Protection Act of 2023 providing stronger consumer protections than were in force at the time of the breach. There has been no public reporting of further large-scale data breaches at Upstox since 2021. ShinyHunters, the threat actor associated with the original incident, has remained one of the most active data-extortion groups globally through 2025 and into 2026.

🔍 Data Points Exposed

13 verified field types:
Bank account numbers
Dates of birth
Email
Family members' names
Genders
Government issued IDs
Income levels
Marital statuses
Nationalities
Occupations
Passwords
Phone numbers
Physical addresses

Exposure Categories

CredentialsGOV ID
LocationPHYS ADDR
FinancialFIN PROFILE | BANK ACCT
EmploymentJOB INFO

Canonical Fields

bank_account_number, date_of_birth, email_address, family_member_names, financial_profile:income, gender, government_id, job_information:occupation, nationality_or_citizenship:nationality, password, phone_number, physical_address, relationship_status:marital

🌐 Dark Web Verification

Confirmed
  • Dataset containing ~111K records identified in breach intelligence sources
  • Data indexed and searchable across breach notification platforms
  • Source: Upstox Data Breach

🛡 Recommended Actions

⚠️ Do not assume this is low sensitivity.

1Freeze Your Credit
Place a credit freeze with Equifax, Experian, and TransUnion.
2Expect Targeted Phishing
Watch for emails referencing this breach. Verify through official channels.
3Enable MFA Everywhere
Enable multi-factor authentication on all accounts.
4Monitor Accounts
Watch for unauthorized activity on financial and personal accounts.
5Check Your Exposure
ObscureIQ clients: this breach is indexed in your profile.

Protect Yourself

Check If You’re Affected

Enter your email to check if your data appears in this breach.

Get Free Breach Alerts

Be the first to know when new breaches are disclosed.

High-Risk? Get an Exposure Audit

Full-spectrum exposure audits for executives and public figures.

Request Consultation

ObscureIQ Advisory

We combine proprietary dark web access with commercial and restricted breach intelligence to verify exposure and assess real-world risk.

If you are:
  • A public-facing individual
  • A high-profile executive
  • A customer of Upstox
  • Or concerned about credential reuse
Services
AuditsWipesThreat MonitoringTraining

Classification Tags

MisconfigurationFinancialEmailPhoneAddressPasswordsGovernmentIDFData

Powered by the ObscureIQ Breach Intelligence Database

© 2026 ObscureIQ · All Rights Reserved · Data Licensing

Latest from ObscureIQ

Credit

What Is Credit Monitoring? And Do I Want It? (Answer: Not Really)

July 14, 2025
Every time there’s a major data breach, companies scramble to offer “free” credit monitoring. It sounds like a responsible move.…
breach economycredit freezecredit scoreequifaxexperian
Credible Threats

Lock Down Browsers. Wipe Employee Footprints. Win Breach Wars.

September 2, 2025
Lock Down Browsers. Wipe Employee Footprints. Win Breach Wars. Over 80% of security incidents now start in the browser. Chrome.…
brave browserbreachesbrowser exploitbrowserschrome
Analysis

Sextortion Spam

May 10, 2025
Sextortion scams aren’t new, but they remain one of the most effective forms of cyber-enabled fraud. These scams don’t rely…
bitcoindeadlinefeargoogle maps apiransom