Language:
⚠️ AI-generated translation. English original is authoritative.
Security Investigation

IDRBT .bank.in: From Trust Anchor to Data Leak

CashlessConsumer  ·  June 28, 2026

India's .bank.in was RBI's flagship anti-phishing initiative — a domain suffix meant to be a trust anchor citizens could rely on. Instead, the very portal that issues these banking domains leaked every credential it held.

The IDRBT Domain Registration Portal (registrar.idrbt.ac.in) — the exclusive registrar for India’s .bank.in banking namespace — exposed its entire REST API via 33+ unauthenticated endpoints. Anyone with curl could retrieve the bcrypt password hashes, mobile numbers, email addresses, login IPs, and device fingerprints of all 5,576 bank employees trusted with managing India’s banking domains.

The portal was built by IKCON Technologies without any public tender, in violation of IDRBT’s own procurement handbook. IKCON employees held 22 accounts including 3 with global Super Admin access.

Think of .bank.in as a special padlock RBI put on every bank website so you know it's real. This investigation found that the padlock maker's own system was leaking all the keys — and the report explains how, why it matters, and what's still broken.

The vulnerability was reported to CERT-In (Jun 8, 05:30 UTC) and confirmed fixed by IDRBT on June 25, 2026. The exposed endpoints are no longer accessible.
📄 Download Full Report (PDF) 📦 Open Data & Datasets

Open Data

DatasetRecordsPublished
Registered .bank.in domains1,497Yes
Domains with active NS1,402Yes
Domains without NS (unpublished to NIXI)95Yes
Billing records (anonymized)1,535Yes
Certificate Transparency log entries3,797Yes
User records (original leak)5,461No — contains PII/hashes
Orphan user records1,072No — contains PII/hashes

Data feeds into the bank-in-domains daily audit (CT logs, Wayback Machine, urlscan.io at 02:30 UTC).

CashlessConsumer

A consumer collective that tracks the digital payments industry in India, producing awareness resources, technical analysis, open data, and policy inputs toward a fair cashless society.

Prior work: KillerLoanApps · BFIL Consent Scam · Fintech Governance RTI Program
cashlessconsumer.in · Newsletter · GitHub