← Back to Breach Management
BR-2026-004Notification in ProgressHigh
Customer Portal Vulnerability
Owner: Priya Mehta – Security · Business unit: Digital · Detected 29 Dec 1969, 10:00 pm
Board Notification SLA
497104h 46m overdue
Detected 29 Dec 1969, 10:00 pm · Deadline 01 Jan 1970, 10:00 pm
Overdue
Detailed Board update: Pending
100% of the 72-hour window elapsed
Incident Summary
A broken object-level authorisation flaw on the customer portal allowed a signed-in user to view another user's profile page.
Breach Details
Occurred
29 Dec 1969, 12:00 pm
Detected
29 Dec 1969, 10:00 pm
Source
Cyber Attack
Detection method
Security Monitoring
Location
Bengaluru, India
Business unit
Digital
Systems affected
Customer Portal, Mobile App
Data Processor
No
Records affected
1,870
Data Principals affected
1,870
Nature of breach
Unauthorized Access, Confidentiality Breach
Data categories
Name, Email, Mobile Number, Address
Risk
71 / 100
High
LowMediumHighCritical
Data sensitivityHigh
Number affectedMedium
External exposureHigh
Financial impactLow
Credential exposureLow
Current Status
Breach lifecycle progress.
- Detected
- Assessment
- Confirmed
- Board Notification
- 5DP NotificationCurrent stage
- 6Remediation
- 7Closed
