India’s .bank.in domain program, launched to improve trust in banking websites and reduce phishing, was hit by allegations that the registration portal run by the Institute for Development and Research in Banking Technology (IDRBT) exposed sensitive data through more than 33 unauthenticated REST API endpoints. Researcher Srikanth L of CashlessConsumer reported that the flaws could have exposed information tied to 5,576 bank employees responsible for managing banking domains, including bcrypt password hashes, mobile numbers, email addresses, login IP addresses, and device fingerprints.
The reported exposure raised concerns that attackers could use the leaked information for impersonation, phishing, and DNS-related attacks against Indian banks. The researcher said the portal remained insecure for about 13 months and lacked a proper security audit, while many .bank.in domains were also found to have weak security hygiene, including limited adoption of DNSSEC and DMARC and, in some cases, hosting on shared international servers. IDRBT reportedly fixed the exposed API flaws after disclosure, while public responses from IDRBT, the Reserve Bank of India, and the Indian government were not available at the time of reporting.

See attribution, scope, and your downstream exposure.
3 events from the most recent confirmed update back to the earliest known activity.
After the disclosure, IDRBT reportedly remediated the exposed API vulnerabilities in its Domain Registration Portal.
According to Srikanth L, the exposed API issue affecting the .bank.in registrar portal was disclosed to IDRBT in early June 2026.
Researcher Srikanth L alleged that IDRBT's .bank.in Domain Registration Portal exposed more than 33 unauthenticated API endpoints for 13 months without a proper security audit, risking access to sensitive data on 5,576 bank employees.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.