Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Nupay

Nupay Vendor Cyber Rating & Cyber Score

nupay.co.in

Nupay is India's Most Comprehensive Fintech Infrastructure Platform for Enterprises. Nupay has Built a Tech stack across payments, collections and Lending which can enables enterprises to build new fintech solutions or embed relevant services in their existing solutions/apps. Nupay’s platform connects with multiple banks and lenders providing an digital, AI/ML enabled interoperable business solutions covering embedded finance (loans), recurring payments - NACH, eMandates, UPI AutoPay, BBPS, EIPP, Automated reconciliations, collections and bank payouts.


Nupay A.I CyberSecurity Scoring

Nupay
Company Information
Website:https://www.nupay.co.in
Employees number:25
Number of followers:2,887
NAICS:52
Industry Type:Financial Services
Homepage:nupay.co.in
Nupay Risk Score (AI oriented)
Between 600 and 649
logo
NupayFinancial Services
Updated:
01/04/2026
616/1000
Poor
Caa
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Nupay Global Score (TPRM)
xxxx
logo
NupayFinancial Services
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Nupay
NupayPoor
Current Score
616Caa (POOR)
01000
2 incidents
0 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
623Before Incident
MAY 2026
620Before Incident
APRIL 2026
617Before Incident
MARCH 2026
616Before Incident
FEBRUARY 2026
613Before Incident
JANUARY 2026
611Before Incident
DECEMBER 2025
608Before Incident
NOVEMBER 2025
605Before Incident
OCTOBER 2025
602Before Incident
SEPTEMBER 2025
599Before Incident
AUGUST 2025
596Before Incident
JULY 2025
593Before Incident
MAY 2025
684Before Incident
Breach
01 May 2025Nupay
Nupay

Major Data Breach Exposes 2,73,000 Sensitive Bank Transfer Documents in India via Unsecured Amazon S3 Server

584After Incident
CRITICAL-100
NUP4762547092725
A critical data breach exposed over 2,73,000 sensitive bank transfer documents in India due to an unsecured Amazon S3 server managed by fintech firm Nupay. The leak, discovered by cybersecurity firm UpGuard, revealed highly confidential financial data, including account numbers, transaction details, and contact information tied to 38 banks. Nupay later acknowledged responsibility, attributing the incident to a 'configuration gap' in their cloud storage setup. The exposed data poses severe risks of financial fraud, identity theft, and reputational damage for affected customers and institutions. The breach underscores vulnerabilities in third-party financial service providers and the critical need for robust cybersecurity measures in handling sensitive banking data. Regulatory scrutiny and potential legal repercussions may follow, given the scale and sensitivity of the compromised information.
INCIDENT DETAILS -
TYPE
data breachmisconfiguration
IMPACT
account numberstransaction detailscontact informationAmazon S3 serverBrand Reputation Impact: high (due to exposure of sensitive financial data)Identity Theft Risk: high (due to exposure of PII and financial data)Payment Information Risk: high (account numbers and transaction details exposed)
DATA BREACH
financial recordspersonal identifiable information (PII)Number Of Records Exposed: 2,73,000+Sensitivity Of Data: high (financial and personal data)Data Exfiltration: yes (data was exposed publicly)Data Encryption: no (data was unsecured)bank transfer documentsPersonally Identifiable Information: yes (account numbers, contact information)
AUGUST 2023
752Before Incident
Breach
01 Aug 2023Nupay
Nupay

Unsecured Cloud Server Exposes 273,000 Sensitive Bank Transfer Documents in India

649After Incident
CRITICAL-103
NUP5192851092625
A misconfigured Amazon S3 storage bucket operated by Indian fintech company Nupay exposed 273,000 sensitive bank transfer documents, including account numbers, transaction details, and personal contact information of Indian customers. The leaked files—linked to 38 banks and financial institutions, prominently featuring Aye Finance and State Bank of India—were part of the National Automated Clearing House (NACH), India’s centralized system for high-volume transactions like salaries and loan repayments.Researchers at UpGuard discovered the publicly accessible bucket in late August 2023, noting that thousands of new files were being added daily even after initial alerts. While Nupay later claimed the exposed data was mostly ‘dummy or test records’, UpGuard disputed this, stating only a few hundred of the sampled files appeared non-sensitive. The bucket’s details were also indexed by Grayhatwarfare, a public database of unsecured cloud storage, raising concerns over potential unauthorized access.The exposure was secured in early September after interventions from CERT-In (India’s cybersecurity agency), but the incident highlighted critical lapses in cloud security protocols, risking financial fraud, identity theft, and reputational damage for affected individuals and institutions. Nupay attributed the breach to a ‘configuration gap’ but provided no clarity on the duration of exposure or evidence ruling out data misuse.
INCIDENT DETAILS -
TYPE
data breachunsecured cloud storagemisconfiguration
IMPACT
bank account numberstransaction figuresindividuals’ contact details (names, addresses, phone numbers)NACH transaction forms (salaries, loan repayments, utility payments)Amazon S3 storage bucketpotential reputational damage to Nupay, Aye Finance, and associated bankshigh (exposed PII and financial data)high (exposed bank account numbers and transaction details)
DATA BREACH
personally identifiable information (PII)financial transaction recordsbank account detailsNACH transaction formsSensitivity Of Data: high (financial and personal data)Data Exfiltration: unconfirmed (publicly accessible but no evidence of unauthorized download)Data Encryption: none (data stored in plaintext PDFs)PDFnamesaccount numberscontact details (phone numbers, addresses)transaction amounts

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Nupay ?
?
What was Nupay's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Nupay's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Nupay's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Nupay's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Nupay's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Nupay's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Nupay's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Nupay's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Nupay's A.I Rankiteo Cyber Score in September 2025 ?
?
What was Nupay's A.I Rankiteo Cyber Score in August 2025 ?
?
What was Nupay's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on Nupay's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Nupay ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Nupay's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?