Breach report
Unauthenticated APIs in .bank.in registrar exposed data on 5,576 bank staff

AI-generated illustration by CyberShitty. Not a photograph or a document from the organisations named.
The portal banks use to register RBI-mandated .bank.in domains left 33+ API endpoints open for at least 13 months. IDRBT fixed it after a CERT-In report.
What happened
The Reserve Bank of India (RBI) created the .bank.in domain in 2025 as a trust marker for bank websites. Registrations run through a portal operated by the Institute for Development and Research in Banking Technology (IDRBT). A researcher with the CashlessConsumer group found that the portal exposed more than 33 API endpoints that needed no login. Anyone could pull the user database. The group's report says the portal had been live in this state for at least 13 months.
Confirmed vs. claimed
Confirmed: the flaw was reported to CERT-In on 8 June 2026. According to the researchers' timeline, IDRBT fixed it on 25 June and CERT-In confirmed the fix on 26 June. The exposed records covered 5,576 bank employee accounts: bcrypt password hashes, mobile numbers, email addresses, login IP addresses and device fingerprints.
Not established: whether anyone else downloaded the data. Neither IDRBT nor RBI had commented publicly when CybersecAsia reported the findings. The researchers also said the portal was built without a public tender, which IDRBT has not addressed publicly.
Who is affected
Bank employees who administer .bank.in domains. Bank customers' account data was not in this system. The risk to customers is indirect: stolen admin details could help someone try to hijack or spoof a bank's domain.
What to do
- Bank IT teams: reset registrar passwords, enforce multi-factor authentication (MFA), and review domain and DNS records for unexpected changes.
- Staff: expect targeted phishing that uses your name, role and registrar context.
- Customers: type your bank's address yourself or use its official app; do not follow links in messages.
- If you lose money, call 1930 or report at cybercrime.gov.in as fast as you can; see our 1930 guide.
Sources
More breaches in India
- Dodo Payments — 17 Aug 2026
- Bank of Baroda — 28 Jul 2026
- Reliance Infrastructure (Kudankulam project data) — 16 Jul 2026
- UMANG (MeitY government services app) — 14 Jul 2026
- National Testing Agency (CUET-UG 2026 candidate data) — 08 Jul 2026