Full Report
In July 2024, the Indian stock brokerage firm Angel One confirmed that data leaked online related to a breach that occurred in April 2023. The leaked data included 7.9M user records containing 6.8M unique email addresses, along with names, physical addresses, phone numbers, bank account numbers, Permanent Account Numbers (PANs) and portfolio holdings. Angel One emphasised that the breach "has no impact on client securities, funds, or credentials".
Analysis Summary
# Incident Report: Angel One Customer Data Leak (April 2023)
## Executive Summary
In July 2024, Indian stockbroker Angel One confirmed a historical data breach involving the unauthorized access of 7.9 million user records. The incident, which originated in April 2023, resulted in the exfiltration of sensitive PII and financial portfolio details, though the firm maintains that core trading credentials and funds remained secure. The breach came to light publicly following the sale or leak of the dataset on the dark web over a year after the initial compromise.
## Incident Details
- **Discovery Date:** July 2024 (Confirmation of public leak)
- **Incident Date:** April 2023
- **Affected Organization:** Angel One
- **Sector:** Financial Services / Stock Brokerage
- **Geography:** India
## Timeline of Events
### Initial Access
- **Date/Time:** April 2023
- **Vector:** Undisclosed (Likely unauthorized access to a database or backend API)
- **Details:** Attackers gained access to customer records containing sensitive personal and financial information.
### Lateral Movement
- **Details:** Not specifically disclosed; however, the scope suggests access to central customer relationship management (CRM) or back-office databases.
### Data Exfiltration/Impact
- **Details:** 7.9 million user records were exfiltrated, containing 6.8 million unique email addresses and associated sensitive metadata.
### Detection & Response
- **Detection:** The breach was officially acknowledged by the firm in July 2024 after the data appeared online.
- **Response actions taken:** Angel One investigated the scope of the leak and issued a public statement clarifying that client funds and trading credentials (passwords/pins) were not impacted.
## Attack Methodology
*Note: Specific technical details regarding the adversary's TTPs were not fully disclosed in the source material.*
- **Initial Access:** Unauthorized access to data storage/database.
- **Persistence:** Unknown.
- **Privilege Escalation:** Unknown.
- **Defense Evasion:** Unknown.
- **Credential Access:** No evidence of trading credential compromise.
- **Discovery:** Targeted customer PII and portfolio holdings.
- **Lateral Movement:** Unknown.
- **Collection:** Automated extraction of 7.9M records.
- **Exfiltration:** Data moved to external attacker-controlled infrastructure.
- **Impact:** Mass data leak and reputational damage.
## Impact Assessment
- **Financial:** No direct loss of client funds reported; however, potential for future regulatory fines and increased security spending.
- **Data Breach:** High. 7.9M records including Names, Emails, Phone Numbers, Physical Addresses, Bank Account Numbers, PANs, and Portfolio Holdings.
- **Operational:** Minimal disruption to daily trading operations reported.
- **Reputational:** Significant. High-profile leak involving sensitive financial data of a major Indian brokerage.
## Indicators of Compromise
- **Network indicators:** Not disclosed.
- **File indicators:** Not disclosed.
- **Behavioral indicators:** Unusual database query volumes or unauthorized API calls in April 2023.
## Response Actions
- **Containment measures:** Security hardening of the affected environment post-April 2023.
- **Eradication steps:** Internal audit of data access logs.
- **Recovery actions:** Public disclosure and assurance to clients regarding the safety of funds and securities.
## Lessons Learned
- **Delayed Disclosure:** The significant gap between the incident (April 2023) and public confirmation (July 2024) highlights a need for better real-time data exfiltration monitoring.
- **Data Sensitivity:** While funds were safe, the loss of PANs and bank account numbers significantly increases the risk of identity theft and targeted phishing for customers.
- **Inventory Management:** The discrepancy between "user records" (7.9M) and "unique emails" (6.8M) suggests duplicate entries or legacy accounts being stored.
## Recommendations
- **Zero Trust Architecture:** Implement strict identity-based access controls for any database containing PII or financial records.
- **Data Masking:** Mask sensitive fields like PAN and Bank Account numbers in non-production environments and for general administrative views.
- **Enhanced Monitoring:** Deploy Data Loss Prevention (DLP) tools to detect large-scale outbound data transfers.
- **Customer Protection:** Provide affected users with credit monitoring services and advise them to update all passwords and enable TOTP-based Two-Factor Authentication (2FA).