← Swiggy

2022 Infrastructure glitch — card/UPI exposure

2022 Unknown records affected Share on X

Data compromised

Partial card digits, UPI handles

Technical writeup

Sep 2022. CERT-In report: infrastructure changes allowed customers to temporarily view last 4 digits of others' card details and UPI handles. Feb 2023: former employee fraudulently accessed test systems; FIR filed. Mar 2024: CERT-In flagged potential third-party leak; provider confirmed Swiggy data not compromised.

Root cause

Infrastructure misconfiguration; insider access (2023).

References