← Back to Breach Management
BR-2026-004Notification in ProgressHigh

Customer Portal Vulnerability

Owner: Priya Mehta – Security · Business unit: Digital · Detected 29 Dec 1969, 10:00 pm

Board Notification SLA
497104h 46m overdue
Detected 29 Dec 1969, 10:00 pm · Deadline 01 Jan 1970, 10:00 pm
Overdue
Detailed Board update: Pending
100% of the 72-hour window elapsed

Incident Summary

A broken object-level authorisation flaw on the customer portal allowed a signed-in user to view another user's profile page.

Breach Details

Occurred
29 Dec 1969, 12:00 pm
Detected
29 Dec 1969, 10:00 pm
Source
Cyber Attack
Detection method
Security Monitoring
Location
Bengaluru, India
Business unit
Digital
Systems affected
Customer Portal, Mobile App
Data Processor
No
Records affected
1,870
Data Principals affected
1,870
Nature of breach
Unauthorized Access, Confidentiality Breach
Data categories
Name, Email, Mobile Number, Address

Risk

71 / 100
High
LowMediumHighCritical
Data sensitivityHigh
Number affectedMedium
External exposureHigh
Financial impactLow
Credential exposureLow

Current Status

Breach lifecycle progress.

  1. Detected
  2. Assessment
  3. Confirmed
  4. Board Notification
  5. 5
    DP Notification
    Current stage
  6. 6
    Remediation
  7. 7
    Closed