Upstox Alerts Users of Security Breach: Says Funds, Securities Remain Safe
Upstox has alerted customers to a security breach that included customer contact details and KYC details. The retail brokerage firm assured users that their funds and securities remain safe.
The development comes shortly after reports of data breaches at organizations like Facebook, LinkedIn, and MobiKwik.
“Upon receiving emails claiming unauthorized access to our database, we have appointed a leading international cybersecurity firm to investigate the potential for breach of some KYC data stored on third-party data storage systems. This morning hackers placed a sample of our data on the dark web, ”a company spokesperson said in an emailed statement.
The spokesperson added that, as a proactive measure, the company has initiated multiple security improvements, particularly in third-party warehouses, 24×7 real-time monitoring and additional protection of its network.
“As a matter of great caution, we have also initiated a secure password reset via OTP for all Upstox users. Upstox takes customer security very seriously. The funds and securities of all Upstox clients are protected and remain safe. We have also duly reported this incident to the relevant authorities, ”the spokesperson said.
The spokesperson further said that at this point, “We do not know for sure the number of customers whose data has been exposed.”
Upstox, backed by investors like Tiger Global and Ratan Tata, has more than three million users. In an announcement note in the Company website, Upstox co-founder and CEO Ravi Kumar said that client funds and securities are protected and remain safe.
“The funds can only be transferred to their linked bank accounts and their values are kept in the corresponding depositories. With great caution, we have also initiated a secure password reset via OTP. Throughout this time, we have also strengthened our systems to the highest standards, ”he said.
Kumar added that the company has restricted access to the affected database and added multiple security enhancements to all third-party data stores.
The company has also stepped up its bug bounty program to encourage ethical hackers to stress-test your systems and protocols and help you identify vulnerabilities from time to time.
The company has urged customers to always use unique strong passwords that are different from previous versions and not to share OTP with anyone. He also urged customers to beware of online fraud and to verify the legitimacy of links and senders, to be vigilant about requested OTPs, and to alert the service provider in such events.

She is a freelance blogger, writer, and speaker, and writes for various entertainment magazines.

