← PayU

2021 LazyPay API vulnerability — sensitive data exposure risk

2021 Unknown records affected Share on X

Data compromised

Names, gender, DOB, phone numbers, KYC status

Technical writeup

Security flaw discovered in LazyPay (PayU's buy-now-pay-later platform). Unsecured API endpoint could have allowed attackers to access sensitive user data including full names, gender, date of birth, phone numbers, and KYC status. PayU fixed the issue immediately after it was reported; no customer information was confirmed leaked.

Root cause

Unsecured API endpoint; insufficient access controls.

References