Last updated 2 weeks ago
The Reserve Bank of India (RBI) mandated the use of .bank domains for financial institutions to enhance trust, but the registry operator's open API leaked sensitive information. The breach was publicly disclosed in June 2026, though the exact discovery date is not specified. The exposure could reveal everything an attacker needs to impersonate bank officials, including names, email addresses, phone numbers, organizational roles, and domain registration details.
The attack vector was a misconfigured open API that allowed unauthorized access to the registry's data. No specific threat actor or ransomware group has been attributed. The exposed data types include personally identifiable information (PII) and organizational details that could facilitate social engineering and impersonation attacks against bank officials.
No post-incident details such as regulatory actions, litigation, ransom payments, or remediation milestones are provided in the article.
Open API misconfiguration exposed sensitive registry data
The RBI's .bank domain registry leak underscores the critical need for rigorous API security controls, especially when handling sensitive organizational data. The misconfiguration allowed unrestricted access to information that could enable impersonation of bank officials, highlighting the importance of implementing proper authentication, authorization, and rate limiting for APIs. Financial regulators and their vendors must prioritize security testing and access controls for any systems that store or expose sensitive data.
Sign in to join the discussion.
Company
Industry
Location
Disclosed
Records Affected
Attack Vector