Menu
Browse

BharatPay

Aliases 2 aliases
Primary URL Location Industry
bharatpe[.]com
Country India
Financial Services Icon
Financial Services
Profile

BharatPay, also operating under the alias BharatPe, is a financial services provider whose headquarters are located in India. The company’s core offering revolves around facilitating digital payments through the Unified Payments Interface (UPI) ecosystem. It maintains user accounts that store personal identifiers such as full names, hashed passwords and mobile phone numbers, together with the associated UPI IDs that enable instant bank‑to‑bank transfers. In addition to authentication data, the platform retains a comprehensive ledger of each customer’s transaction history, covering multiple years and including the corresponding bank balances at the time of each operation. Beyond the consumer‑facing payment layer, BharatPay holds official contact information for the partner banks that sponsor its UPI infrastructure, which is used for settlement and reconciliation purposes. The organisation also safeguards API keys that grant access to critical utility services required for payment processing, as well as callback logs that capture detailed records of every transaction request and response. These combined data assets illustrate the breadth of information that the firm manages in the course of delivering its financial services.

On 13 August 2022, BharatPay suffered a significant data breach that exposed the personal and transactional details of approximately 37,000 of its users. The compromised dataset included names, hashed passwords, phone numbers, UPI IDs, bank balances and multi‑year transaction records, thereby providing a comprehensive view of each affected individual’s financial activity. In addition to user‑specific information, the breach disclosed official employee contact details belonging to the partner banks that collaborate with BharatPay on payment settlement. The attackers also exfiltrated API keys for essential services that the organisation relies on to interact with banking networks and payment gateways, as well as callback logs that contain further granular transactional data such as timestamps, amounts and status codes. Investigators traced the intrusion to vulnerabilities in outdated software components that permitted prototype pollution and, consequently, remote code execution on the affected servers. A threat actor who has previously claimed responsibility for attacks against other financial institutions asserted that they were behind this intrusion and released the stolen data online. Despite the public disclosure of the breach, BharatPay has not issued a detailed remediation plan outlining the specific steps taken to secure its systems or mitigate the risk of future incidents.

Incidents
Linked incidents available to members
1 incident