The sole registrar for India's mandatory .bank.in banking domains allegedly exposed sensitive data on thousands of bank staff through open web API endpoints. Researcher Srikanth L said IDRBT's registration portal exposed 33+ unauthenticated REST endpoints that returned bcrypt password hashes, mobile numbers, email addresses, login IP addresses, and device fingerprints for 5,576 employees managing bank domains; the issue was reportedly disclosed in early June 2026 and later fixed.
Why it matters: This could have given attackers the exact information needed to impersonate bank officials, target domain administrators, and abuse banking-domain trust for phishing or account takeover. Indian banks and regulators should review registrar access logs, rotate credentials, harden domain security controls such as DNSSEC and DMARC, and warn staff about targeted social engineering.
2026.06.30
100% relevant
This article appears to be the first tracked report of the IDRBT .bank.in registrar exposure and establishes the core event: unauthenticated API access leaking sensitive bank-domain administration data.
← Back to all stories