Supply chain β›“ Supply Chain

Upstox Third-Party Breach (April 2021)

πŸ“… 2021-04-01 🏒 Not disclosed
Primary Source β†—

Incident Details

Upstox alerts its users of data breach; funds, securities safe. On receipt of e-mails claiming unauthorized access into Upstox database, the company has appointed a cyber-security firm to investigate possibilities of breach of some KYC data stored in third-party data warehouse systems. Retail broking firm Upstox has alerted customers of a security breach that included contact data and KYC details of customers, but assured users that their funds and securities remain safe. The development comes close on the heels of reports of data breaches at organizations like MobiKwik, Facebook and LinkedIn.

Technical Details

Initial Attack Vector
Compromise of third-party service provider / vendor relationship
Vendor / Product
Not disclosed
Supply Chain Attack
βœ… Confirmed third-party / vendor compromise

Timeline

  1. 2021-04-01 Breach occurred
  2. 2021-04-12 Publicly disclosed