Supply chain
β Supply Chain
Upstox Third-Party Breach (April 2021)
Primary Source βIncident Details
Upstox alerts its users of data breach; funds, securities safe. On receipt of e-mails claiming unauthorized access into Upstox database, the company has appointed a cyber-security firm to investigate possibilities of breach of some KYC data stored in third-party data warehouse systems. Retail broking firm Upstox has alerted customers of a security breach that included contact data and KYC details of customers, but assured users that their funds and securities remain safe. The development comes close on the heels of reports of data breaches at organizations like MobiKwik, Facebook and LinkedIn.
Technical Details
- Initial Attack Vector
- Compromise of third-party service provider / vendor relationship
- Vendor / Product
- Not disclosed
- Supply Chain Attack
- β Confirmed third-party / vendor compromise
Timeline
- 2021-04-01 Breach occurred
- 2021-04-12 Publicly disclosed