Tech Souls, Connected.

Aye Finance Denies Breach After 2.7 Lakh NACH Files Exposed via Partner

Over 2.7 Lakh sensitive NACH documents were exposed via a misconfigured cloud bucket linked to Aye Finance’s integration partner, spotlighting urgent data security challenges in India’s fintech ecosystem.


Major Data Exposure Linked to NACH Mandates

In August 2025, cybersecurity firm UpGuard uncovered a massive data exposure involving over 2.73 lakh (273,160) PDF files related to National Automated Clearing House (NACH) transactions.

  • The exposed files, totaling 210 GB, contained bank account numbers, customer names, emails, phone numbers, and transaction details.
  • The documents involved at least 38 banks and financial institutions, with Aye Finance appearing in nearly 60% of the samples reviewed.
  • Other entities involved included SBI (24.2%), Bank of Baroda, PNB, and Muthoot Capital.

Aye Finance Denies Fault, Points to Vendor

Aye Finance, which is preparing for its IPO, clarified that its own systems were not compromised.

  • The company stated that no NACH mandate forms were stored in its AWS S3 storage, eliminating the possibility of a direct breach.
  • Instead, the issue was traced to Nupay, Aye Finance’s integration partner for NACH management.
  • Nupay acknowledged the misconfiguration and confirmed that the exposed Amazon cloud storage bucket was secured in early September.

No Critical Identity Documents Leaked

According to Aye Finance, Nupay has confirmed that no signed ACH forms, Aadhaar, or PAN card data of customers were part of the breach.

  • The exposed documents carried the metadata tag “NACH MANDATE.cdr” and were related to bulk payment collections.
  • Nupay also provides services to Tata Capital, Bajaj Finserv, and HDB Financial Services, amplifying concerns over potential exposure.

NPCI and CERT-In Respond

Following the discovery, UpGuard alerted Aye Finance, NPCI, and CERT-In. NPCI’s Cyber Security Incident Response Team (CSIRT) responded on September 23, stating:

“No data related to NACH mandate information from NPCI systems has been exposed. The data in question does not belong to NPCI.”

  • NPCI also reaffirmed that its systems are secure and compliant with data governance standards.
  • The exposed data appears to have originated entirely from third-party vendor infrastructure, not the core NACH platform.

Highlights Security Weakness in India’s Fintech Stack

This incident underscores persistent cloud security gaps and the lack of accountability in third-party vendor management:

  • The public exposure of sensitive financial data due to basic misconfiguration reflects the fragile perimeter of digital infrastructure.
  • The lack of standardized cloud security audits for vendors remains a critical risk to consumer data protection.

A Pattern of Breaches in India

The Aye Finance-Nupay breach is not an isolated case. India’s tech and fintech sectors have witnessed several high-profile data exposures recently:

  • June 2025: A hacker accessed data of 8.4 Mn Zoomcar users.
  • 2024: Personal data of millions of Star Health Insurance customers was sold via Telegram.

These incidents reveal a pattern of insufficient cybersecurity practices in India’s growing digital economy—especially concerning given the sensitive nature of fintech data.

Share this article
Shareable URL
Prev Post

BharatPe Slashes Losses by 82%, Inches Toward Profitability in FY25

Next Post

Innov8’s FY25 Profit Plunges 97% Despite Strong Workspace Growth

Read next