India's .bank.in was RBI's flagship anti-phishing initiative — a domain suffix meant to be a trust anchor citizens could rely on. Instead, the very portal that issues these banking domains leaked every credential it held.
The IDRBT Domain Registration Portal (registrar.idrbt.ac.in) — the exclusive registrar for India’s .bank.in banking namespace — exposed its entire REST API via 33+ unauthenticated endpoints. Anyone with curl could retrieve the bcrypt password hashes, mobile numbers, email addresses, login IPs, and device fingerprints of all 5,576 bank employees trusted with managing India’s banking domains.
The portal was built by IKCON Technologies without any public tender, in violation of IDRBT’s own procurement handbook. IKCON employees held 22 accounts including 3 with global Super Admin access.
Think of .bank.in as a special padlock RBI put on every bank website so you know it's real. This investigation found that the padlock maker's own system was leaking all the keys — and the report explains how, why it matters, and what's still broken.
| Dataset | Records | Published |
|---|---|---|
| Registered .bank.in domains | 1,497 | Yes |
| Domains with active NS | 1,402 | Yes |
| Domains without NS (unpublished to NIXI) | 95 | Yes |
| Billing records (anonymized) | 1,535 | Yes |
| Certificate Transparency log entries | 3,797 | Yes |
| User records (original leak) | 5,461 | No — contains PII/hashes |
| Orphan user records | 1,072 | No — contains PII/hashes |
Data feeds into the bank-in-domains daily audit (CT logs, Wayback Machine, urlscan.io at 02:30 UTC).
A consumer collective that tracks the digital payments industry in India, producing awareness resources, technical analysis, open data, and policy inputs toward a fair cashless society.