Upstox 2021 Data Breach

Upstox Indian Brokerage Platform Breach (2021): Bank Account Numbers, Government ID, Income & Family Member Names Exposed

Financial institution · Investment and trading services · Brokerage platform · India

Upstox Indian Brokerage Platform Breach (2021): Bank Account Numbers, Government ID, Income & Family Member Names Exposed

Indian online brokerage and investment platform.

Confirmed · ObscureIQ Intelligence
Breach Risk Index i
60/100
Lower riskHigher risk
Moderate: notable exposure with meaningful misuse potential.
Data Sensitivity i
Elevated
Exposed data raises the risk of fraud, targeting, and impersonation. Proactive steps are warranted.
111KRecords
2021Year

The Breach Risk Index (BRI) is a proprietary 0–100 score rating how dangerous a breach is right now, based on how recently the data has been circulating on the dark web and how valuable it is to attackers.

Crucial data exposed
Gov IDGovernment ID
FinancialBank Account Number
AddressPhysical address
Classification Tags
ShinyHuntersCloud MisconfigurationFinancial Services2021

Breach Summary

Upstox, one of India's largest online retail brokerage platforms, suffered a data breach in April 2021. Information from the breach circulated on data-trading forums and was indexed by Have I Been Pwned in early 2022. The threat actor responsible has been associated with the ShinyHunters cybercrime collective, which has been linked to a long series of data-theft and extortion campaigns against companies in India and elsewhere.\n\nThe exposed dataset covered approximately 111,000 customer records. Compromised fields formed an unusually deep know-your-customer profile, including names, dates of birth, gender, marital status, nationality, occupation, income levels, family member names, government-issued identification documents, bank account numbers, physical addresses, phone numbers, email addresses, and passwords stored as bcrypt hashes. The dataset also reportedly contained scanned identity documents, bank statements, and cancelled cheques associated with the platform's KYC onboarding process. Bcrypt is a strong password-hashing algorithm, which limits the immediate risk of password recovery, but the surrounding identity, financial, and family data is not similarly protected.\n\nFor affected individuals, the practical risk is severe and durable. The combination of Aadhaar or PAN identifiers with bank account numbers, family member names, and address creates a strong foundation for synthetic identity fraud, fraudulent loan applications, and impersonation at both Indian financial institutions and government services. Family member names create additional risk of family-emergency scams. Income and occupation fields support targeted financial-product fraud. Affected Upstox customers should treat their KYC data as durably exposed, monitor bank and broker accounts closely, and remain alert to unsolicited contact referencing past trading activity, family members, or Aadhaar-related verification.

Full threat analysis, exploitation vectors, and principal guidance below.

11 additional sections · verified field analysis · defensive doctrine

Querying breach corpus…
Cross-referencing exposed field types…
Resolving threat-actor attribution…
Compiling principal risk advisory…

111K records analyzed

About Upstox

Upstox is one of India's largest online retail brokerage platforms, operated by RKSV Securities India Pvt. Ltd. Headquartered in Mumbai and backed by investors including Tiger Global, Ratan Tata, and Kalaari Capital, the platform offers commission-free equity trading, mutual funds, futures and options, and digital onboarding for retail investors. Indian regulatory requirements mean the platform collects an unusually deep set of know-your-customer (KYC) records during account opening, including government-issued identity documents, bank account verifications, income proofs, and family-relationship declarations. The customer base is heavily concentrated in India and skews toward first-time and digitally native retail investors.

Why They Hold Your Data

Brokerage platforms collect customer identity, account details, bank-linkage records, trading activity, balances, device metadata, and compliance documentation across investment workflows.

Recent Developments

Upstox has continued to grow rapidly in the Indian retail-investing market in the years since the 2021 incident, supported by the broader expansion of digital trading platforms among Indian retail investors. The company stated at the time that it had reset customer passwords and secured affected systems. Indian regulatory frameworks have since matured significantly, with the Digital Personal Data Protection Act of 2023 providing stronger consumer protections than were in force at the time of the breach. There has been no public reporting of further large-scale data breaches at Upstox since 2021. ShinyHunters, the threat actor associated with the original incident, has remained one of the most active data-extortion groups globally through 2025 and into 2026.

Data Points Exposed

13 verified field types
Bank Account Number Critical
Date of Birth High
Email Address
Family Member Names
Financial Profile
Gender
Government ID Critical
Job Information
Nationality Or Citizenship
Password High
Phone Number
Physical address High
Relationship Status

Breach Impact

The 2021 breach drew sharp public scrutiny in India and contributed to wider regulatory momentum on consumer data protection in the financial services sector. Upstox publicly acknowledged the incident, reset customer passwords, and engaged external incident-response specialists. The company stated that it had also notified Indian authorities. Public reporting did not surface specific regulatory penalties or settlement outcomes tied to the breach, in part because India's modern data-protection law was not yet in force. The reputational damage was meaningful given the platform's rapid customer-acquisition strategy and competitive positioning, and the breach has continued to be cited in coverage of Indian fintech security as a reference incident.

Exploitation & Downstream Threats

• Credential stuffing against reused passwords across other platforms | • Financial fraud using exposed financial profile data | • Identity theft and synthetic identity construction using government-issued IDs | • SIM swap attacks where phone numbers are present | • Targeted phishing campaigns using exposed email addresses | • Doxxing risk from physical address exposure | • Employment-based social engineering using job and employer data

Principal Risk Advisory

What this means for a principal

A financial-institution breach: account, wealth or payment data supports direct fraud and highly credible financial-impersonation scams. For a high-profile principal this is targeting-grade, not merely identity-theft-grade: the combination lets an adversary locate, impersonate, or pressure the principal with little additional work.

What You Should Do

  1. Freeze credit at all three bureaus and monitor for new-account and tax-refund fraud.
  2. Treat the home address as exposed: review mail and package handling and physical-security routines, and brief household staff to verify unusual requests.
  3. Reset any reused passwords and enable MFA on email first, then financial accounts.
  4. Guard against SIM-swap and vishing: add a carrier port-out PIN and verify any 'support' calls independently.
  5. Do not use unofficial 'am I affected' lookups; several are themselves harvesting operations.

How ObscureIQ Can Help

  1. Corpus confirmation: determine whether and where the principal (plus household and staff) appear in this dataset and which specific fields are exposed for them.
  2. Exposure mapping and footprint neutralization: cross-reference against broker-available data and suppress still-removable elements, prioritizing address and phone, since this record re-seeds broker networks.
  3. ThreatWatch tuned to this incident's identifiers and misuse pattern (impersonation and targeting patterns, not generic credential monitoring).
S
Threat Actor: ShinyHuntersConfidence: High
Data theft / extortion group

Motivation: Financial extortion, data sale
A prolific data theft and extortion group that began as a database theft and resale actor and evolved toward SaaS-focused extortion. Recent activity involves vishing, credential harvesting, SSO compromise, and theft of customer data from cloud and SaaS environments.

Read the full threat-actor profile →

Protect Yourself

Check If You're Affected

Enter your email to check whether your data appears in this breach. We’ll send a 6-digit code to confirm it’s your address.

Get Free Breach Alerts

Be the first to know when new breaches are disclosed. Free forever — confirm your email with a 6-digit code.

High-Risk? Get an Exposure Audit

Executives, public figures, and high-visibility operators can receive tailored exposure intelligence and hardening guidance.

Request Consultation