India-Based Loan App Exposed Millions Of Its Users’ Data In An Unsecured Server

Moneed is an India micro-lending app. Founded in 2018, it may have exposed personal details of many of its Indian users.

The vulnerability was discovered by security researcher Anurag Sen, who informed the company about the issue.

The database which is located on an open elastic server, is said to contain more than 350 million records of Indian users, including their names, phone numbers, information about the phone being used, IP addresses of users, installed apps on phones, and more.

The database was stored in a server provided by Hangzhou Alibaba advertising Co. Ltd. in China, despite the company's founder, Leon Xu, claimed that all Indian data is stored in Mumbai.

In a conversation with Mint, Xu said the Moneed has millions of users in India. He denied that the data belonged to Moneed at first, and said the researcher hadn’t reached out to the company.

However, he later said he would check with his teams about the issue.

In an official statement, the company said:

"We have also thoroughly checked every part of our internal technology system with strengthening our firewall and security protection to completely meet the standards and requirements according to the laws and regulations set forth by the authorities."

While the company didn’t really acknowledge the data breach, it did say that the team has taken suggestions from cybersecurity researchers.

The company that has offices in Hangzhou, New Delhi, and Hong Kong, also said to have replied to the researcher's email.

The researcher, though, said that all he received from the company was a single email, with a statement similar to the one put on its social platforms and sent to the media.

[block:block=87]

It should be noted that Moneed as a company, has had two Android apps for securing loans. The first is Moneed, and the second was Momo.

The two apps apparently ask for lots of permissions, including access to users' contacts, phone, storage and location. The permissions list for that app even said that it can control a phone’s vibration, connect and disconnect from Wi-Fi networks, have full network access, read content on the phone, and more.

The apps are capable of uploading users' contact list, even before they are used.

The database is said to have contained data gathered between August 2019 and July 2020.

The discovery comes in the wake of anti-China sentiments across government authorities and citizens in India, who are becoming increasingly worried by its neighboring country's powerful operations in the cyberspace.

More recently, India has banned 59 Chinese apps including TikTok for allegedly “stealing and surreptitiously transmitting users’ data in an unauthorized manner to servers which have locations outside India.”