NewsBytes
    Hindi Tamil Telugu
    More
    In the news
    Narendra Modi
    Amit Shah
    Box Office Collection
    Bharatiya Janata Party (BJP)
    OTT releases
    Hindi Tamil Telugu
    NewsBytes
    User Placeholder

    Hi,

    Logout

    India
    Business
    World
    Politics
    Sports
    Technology
    Entertainment
    Auto
    Lifestyle
    Inspirational
    Career
    Bengaluru
    Delhi
    Mumbai

    Download Android App

    Follow us on
    • Facebook
    • Twitter
    • Linkedin
    Home / News / Technology News / #BugAlert: Airtel security flaw risked over 300 million subscribers' data
    Next Article
    #BugAlert: Airtel security flaw risked over 300 million subscribers' data

    #BugAlert: Airtel security flaw risked over 300 million subscribers' data

    By Shubham Sharma
    Dec 09, 2019
    11:11 am

    What's the story

    Leading telecom operator Airtel risked the personal data of its subscribers, more than 300 million people, due to a critical security flaw in its mobile app.

    The issue existed in the Application Program Interface or API of the Airtel app but was prevented from being exploited after the folks at BBC alerted the company.

    Here's all about it.

    Issue

    API issue opened way to steal personal information

    The security flaw, discovered by independent security researcher Ehraz Ahmed, was associated with an API being tested within the Airtel app.

    The issue opened a way for any malicious party to steal the personal information of more than 300 million Airtel subscribers, starting from their names, emails, and birthdate to residential addresses and IMEIs, using nothing but mobile numbers.

    Discovery

    Ahmed found the bug in just 15 minutes

    Ahmed told BBC that it took him just 15 minutes to find this bug and any person with basic technical know-how could have done the same with ease.

    Plus, along with subscriber information, the issue also revealed information like "Subscription Information, Device Capability information for 4G, 3G & GPRS, Network Information, Activation Date, [and] User Type [Prepaid/Postpaid]," Ahmed added while detailing the bug.

    Impact

    This could have triggered a wave of spam, phishing attacks

    As the bug triggered with mobile numbers, a potential attacker could have easily used randomly generated Airtel numbers to mine the personal details of many of Airtel's 300 million+ subscribers.

    Then, using those details, they could have carried out planned phishing attacks to trick users into giving away their money or even more confidential information, like banking or credit/debit card details.

    Fix

    Thankfully, Airtel patched the flaw on time

    While the issue posed a major security threat, Airtel was able to issue a fix without any damage.

    "There was a technical issue in one of our testing APIs, which was addressed as soon as it was brought to our notice," an Airtel spokesperson told the BBC while stressing on the company's efforts to protect the privacy of its subscribers.

    Quote

    Commitment to keep products secure

    "Airtel's digital platforms are highly secure," the Airtel spokesperson added in the statement. "Customer privacy is of paramount importance to us and we deploy the best of solutions to ensure the security of our digital platforms."

    Facebook
    Whatsapp
    Twitter
    Linkedin
    Related News
    Latest
    Security
    BBC

    Latest

    Metallica concert just caused a small quake!  Celebrity
    This US drone uses AI to pick its own targets United States of America
    We both know where he's going: Slot on Alexander-Arnold's future Trent Alexander-Arnold
    Arvind Swami's 'Major Srinivasan' unveiled in Anupam's 'Tanvi The Great' Anupam Kher

    Security

    WhatsApp's 'Delete for everyone' option doesn't work for some users iPhone
    Google removes nearly 50 apps from Chinese developer: Details here Google
    iOS exploit puts millions of iPhones at risk: Details here iPhone
    OYO caught leaking personal customer data, phone numbers India

    BBC

    Shelby-family heads to silver-screen: 'Peaky Blinders' movie is 'being written' Hollywood
    Tributes paid to Indira Gandhi on her 101st birth anniversary Narendra Modi
    Khashoggi-probe: Crown Prince a red line, says Saudi Foreign Minister Donald Trump
    Female Ballon d'Or winner asked to twerk by event's host UEFA Champions League
    Indian Premier League (IPL) Celebrity Hollywood Bollywood UEFA Champions League Tennis Football Smartphones Cryptocurrency Upcoming Movies Premier League Cricket News Latest automobiles Latest Cars Upcoming Cars Latest Bikes Upcoming Tablets
    About Us Privacy Policy Terms & Conditions Contact Us Ethical Conduct Grievance Redressal News News Archive Topics Archive Download DevBytes Find Cricket Statistics
    Follow us on
    Facebook Twitter Linkedin
    All rights reserved © NewsBytes 2025