Over 2.7 Lakh sensitive NACH documents were exposed via a misconfigured cloud bucket linked to Aye Finance’s integration partner, spotlighting urgent data security challenges in India’s fintech ecosystem.
Major Data Exposure Linked to NACH Mandates
In August 2025, cybersecurity firm UpGuard uncovered a massive data exposure involving over 2.73 lakh (273,160) PDF files related to National Automated Clearing House (NACH) transactions.
- The exposed files, totaling 210 GB, contained bank account numbers, customer names, emails, phone numbers, and transaction details.
- The documents involved at least 38 banks and financial institutions, with Aye Finance appearing in nearly 60% of the samples reviewed.
- Other entities involved included SBI (24.2%), Bank of Baroda, PNB, and Muthoot Capital.
Aye Finance Denies Fault, Points to Vendor
Aye Finance, which is preparing for its IPO, clarified that its own systems were not compromised.
- The company stated that no NACH mandate forms were stored in its AWS S3 storage, eliminating the possibility of a direct breach.
- Instead, the issue was traced to Nupay, Aye Finance’s integration partner for NACH management.
- Nupay acknowledged the misconfiguration and confirmed that the exposed Amazon cloud storage bucket was secured in early September.
No Critical Identity Documents Leaked
According to Aye Finance, Nupay has confirmed that no signed ACH forms, Aadhaar, or PAN card data of customers were part of the breach.
- The exposed documents carried the metadata tag “NACH MANDATE.cdr” and were related to bulk payment collections.
- Nupay also provides services to Tata Capital, Bajaj Finserv, and HDB Financial Services, amplifying concerns over potential exposure.
NPCI and CERT-In Respond
Following the discovery, UpGuard alerted Aye Finance, NPCI, and CERT-In. NPCI’s Cyber Security Incident Response Team (CSIRT) responded on September 23, stating:
“No data related to NACH mandate information from NPCI systems has been exposed. The data in question does not belong to NPCI.”
- NPCI also reaffirmed that its systems are secure and compliant with data governance standards.
- The exposed data appears to have originated entirely from third-party vendor infrastructure, not the core NACH platform.
Highlights Security Weakness in India’s Fintech Stack
This incident underscores persistent cloud security gaps and the lack of accountability in third-party vendor management:
- The public exposure of sensitive financial data due to basic misconfiguration reflects the fragile perimeter of digital infrastructure.
- The lack of standardized cloud security audits for vendors remains a critical risk to consumer data protection.
A Pattern of Breaches in India
The Aye Finance-Nupay breach is not an isolated case. India’s tech and fintech sectors have witnessed several high-profile data exposures recently:
- June 2025: A hacker accessed data of 8.4 Mn Zoomcar users.
- 2024: Personal data of millions of Star Health Insurance customers was sold via Telegram.
These incidents reveal a pattern of insufficient cybersecurity practices in India’s growing digital economy—especially concerning given the sensitive nature of fintech data.








