Search

Policybazaar Vulnerabilities Exposed Personal Details of Lakhs of Customers, Defence Personnel: Report

Security firm CyberX9 said the designation of defence personnel, location of their posting and activities they are engaged in were exposed.

Advertisement
Highlights
  • Policybazaar was notified of the security vulnerabilities on July 18
  • The vulnerabilities potentially exposed data of 56.4 million people
  • Policybazaar vulnerabilities were reported to Cert-In on July 24
Policybazaar Vulnerabilities Exposed Personal Details of Lakhs of Customers, Defence Personnel: Report

Policybazaar is said to have admitted and fixed the reported vulnerabilities by July 25

Photo Credit: Pexels/Sora Shizamaki

Vulnerabilities in the system of online insurance broker Policybazaar led to exposure of personal details of lakhs of its customers, including defence personnel, a cyber security research firm claimed on Wednesday. CyberX9 said Aadhaar and PAN card details as well as addresses and phone numbers of customers were exposed due to the vulnerabilities and that the issue was reported to Policybazaar on July 18.

On July 24, Policybazaar informed stock exchanges that it had noticed the vulnerabilities on July 19 and that no significant customer data was exposed.

When contacted on Wednesday, a Policybazaar spokesperson referred to its filing to the stock exchanges made on July 24 and said the identified vulnerabilities have been duly fixed as confirmed by an external advisor.

"A thorough forensic audit of the incident has been initiated with external advisors. The incident was covered by the media. We have nothing further to add," the spokesperson said in a statement.

The online broker's parent PB Fintech is listed on the stock exchanges.

In its report, CyberX9 claimed Policybazaar exposed all confidential and sensitive personal information, including that of Aadhaar, PAN card and passport, of millions of the customers.

It also claimed that the vulnerabilities in Policybazaar's system potentially exposed data of 56.4 million people who have transacted on the platform.

"The information exposed to the whole Internet included but not limited to, customer's full name, date of birth, complete residential address, email address, mobile number, policy details, including nominee details, copies of user's bank account statements, income tax returns documents, passport, Aadhaar card, PAN card, and so on," it said.

In case of the defence personnel, information such as designation, location of their posting and activities they are engaged in were exposed, the report claimed.

After informing Policybazaar about the vulnerabilities on July 18, CyberX9 reported the incident to cyber security watchdog Cert-In on July 24.

"Cert-In confirmed to us on July 25 that Policybazaar has now admitted and fixed the reported vulnerabilities and asked us to retest if the vulnerabilities were fixed," the report said.

CyberX9 said it also submitted the report to National Cyber Security Coordinator Rajesh Pant who promised to initiate action against Policybazaar.

"Rajesh Pant promptly reverted back to us after going through the information we shared, they thanked us for the information and informed us that they shall initiate action against Policybazaar," the report said.

An email query sent to Pant on the issue remained unanswered.

"At the end of our analysis, we came to the conclusion that there is high potential that Policybazaar could be having these vulnerabilities as intentional backdoor vulnerabilities in order to potentially allow access to the Chinese government to sensitive data of Indian nationals and particularly defense personnel," CyberX9 alleged.

China-based Tencent is one of the investors in Policybazaar.


How is Alexa faring in India? We discuss this on Orbital, the Gadgets 360 podcast. Orbital is available on Spotify, Gaana, JioSaavn, Google Podcasts, Apple Podcasts, Amazon Music and wherever you get your podcasts.
Affiliate links may be automatically generated - see our ethics statement for details.

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Further reading: Policybazaar, Vulnerabilities
 
Show Full Article
Please wait...
Advertisement
Popular Mobile Brands
  1. iQOO Z10 Turbo Pro to Be the First Phone to Use Snapdragon 8s Gen 4 SoC
  2. iPhone 17 Pro Could Feature This Flexible 48-Megapixel Telephoto Camera
  3. Motorola Edge 60 Design Renders, Colourways, Key Features Surface Online
  4. Poco C71 With 5,200mAh Battery Launched in India: See Price, Availability
  5. Google Rolls Out Android 16 Beta 3.2 Update for Pixel With These Fixes
  6. WhatsApp May Bring Advanced Chat Privacy Feature to Limit Message Sharing
  7. Honor Play 60, Play 60m With MediaTek Dimensity 6300 SoC Launched
  8. WhatsApp Could Soon Suggest Topics to Chat With Meta AI
  9. Apple Updates These iWork Apps to Support Apple Intelligence Features
  1. Anti-CBDC Bill Cleared by House Financial Services Committee in US: Details
  2. Lumio Vision 7, Vision 9 Features Teased Ahead of April 10 Launch; Dolby Vision, 30W Speakers Confirmed
  3. Xiaomi QLED TV X Pro Series India Launch Date Set for April 10
  4. Samsung Galaxy A55 5G Said to Be Receiving Android 15-Based One UI 7 Beta Update in South Korea
  5. Midjourney Releases V7 Image Generation Model in Alpha, Comes With a Faster and Cheaper Draft Mode
  6. Xiaomi Mix Flip 2 Allegedly Listed on China’s 3C; May Offer Same Charging Speed as Predecessor
  7. Realme GT 7 Confirmed to Get 7,000mAh Battery With 100W Fast Charging
  8. Oppo Find X9 Series Tipped to Feature 200-Megapixel Main or Periscope Zoom Camera
  9. Amazon Is Adding an AI-Powered ‘Recaps’ Feature to Kindle Devices
  10. Honor Play 60, Honor Play 60m With MediaTek Dimensity 6300 SoC, 6,000mAh Battery Launched
Gadgets 360 is available in
Download Our Apps
App Store App Store
Available in Hindi
App Store
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.
Trending Products »
Latest Tech News »