Breach tracker

Breach report

Unauthenticated APIs in .bank.in registrar exposed data on 5,576 bank staff

ConfirmedDisclosed IndiaFinanceBy Vivek Kumar
Records 5.6KCause Vulnerability
Conceptual illustration: A generic bank-staff directory card beside an institutional building sculpture and glass network registry with a narrow security fracture. Headline: IDRBT DATA EXPOSURE.

AI-generated illustration by CyberShitty. Not a photograph or a document from the organisations named.

The portal banks use to register RBI-mandated .bank.in domains left 33+ API endpoints open for at least 13 months. IDRBT fixed it after a CERT-In report.

What happened

The Reserve Bank of India (RBI) created the .bank.in domain in 2025 as a trust marker for bank websites. Registrations run through a portal operated by the Institute for Development and Research in Banking Technology (IDRBT). A researcher with the CashlessConsumer group found that the portal exposed more than 33 API endpoints that needed no login. Anyone could pull the user database. The group's report says the portal had been live in this state for at least 13 months.

Confirmed vs. claimed

Confirmed: the flaw was reported to CERT-In on 8 June 2026. According to the researchers' timeline, IDRBT fixed it on 25 June and CERT-In confirmed the fix on 26 June. The exposed records covered 5,576 bank employee accounts: bcrypt password hashes, mobile numbers, email addresses, login IP addresses and device fingerprints.

Not established: whether anyone else downloaded the data. Neither IDRBT nor RBI had commented publicly when CybersecAsia reported the findings. The researchers also said the portal was built without a public tender, which IDRBT has not addressed publicly.

Who is affected

Bank employees who administer .bank.in domains. Bank customers' account data was not in this system. The risk to customers is indirect: stolen admin details could help someone try to hijack or spoof a bank's domain.

What to do

  • Bank IT teams: reset registrar passwords, enforce multi-factor authentication (MFA), and review domain and DNS records for unexpected changes.
  • Staff: expect targeted phishing that uses your name, role and registrar context.
  • Customers: type your bank's address yourself or use its official app; do not follow links in messages.
  • If you lose money, call 1930 or report at cybercrime.gov.in as fast as you can; see our 1930 guide.

Sources

More breaches in India