High

Angel One: 6.8M Users Exposed in Broker Data Breach

By Yazoul AI · automated

In July 2024, the Indian stock brokerage firm Angel One confirmed that data leaked online related to a breach that occurred in April 2023 . The leaked data included 7.9M user records containing 6.8M unique email addresses, along with names, physical addresses, phone numbers, bank account numbers, Pe...

Overview

Angel One, one of India’s largest retail stock brokerages, confirmed in July 2024 that a trove of customer data had surfaced online, tied to an intrusion that actually took place in April 2023. The leaked file contained roughly 7.9 million user records, of which about 6.8 million were unique email addresses. In total, 6,765,054 accounts are confirmed affected.

The disclosure only became public after the data was loaded into Have I Been Pwned, the breach-notification service run by security researcher Troy Hunt. The 15-month gap between the intrusion and confirmation is one of the more troubling details of this case.

Angel One’s official line is that the breach “has no impact on client securities, funds, or credentials.” That may be true for trading accounts directly, but it sidesteps what was actually taken.

What Was Exposed

According to the leaked dataset, the records include:

  • Email addresses (6.8 million unique)
  • Full names
  • Phone numbers
  • Physical addresses
  • Bank account numbers
  • Permanent Account Numbers (PANs) - India’s national tax ID
  • Portfolio holdings

Angel One’s statement emphasized securities and credentials were untouched, but it did not dispute the presence of bank account numbers, PANs, or portfolio data in the leak.

Why This Combination Is Dangerous

Individually, an email or phone number is low-value. Combined, this dataset is a turnkey identity-theft kit.

Your PAN is the master key for Indian financial identity. It links to tax filings, loan applications, demat accounts, and KYC records. With a PAN, name, and phone number, fraudsters can attempt to open accounts, file fraudulent returns, or impersonate you with lenders.

Bank account numbers plus a name and phone number are exactly what vishing (voice phishing) scammers need to sound credible. A caller who already knows your bank, your name, and your address is far more convincing than a cold caller.

Portfolio holdings are a profiling goldmine. They tell an attacker how wealthy you are and which brokers or assets you use, making you a better-targeted mark for investment fraud.

What to Do Right Now

  1. Check Have I Been Pwned. Visit haveibeenpwned.com and search your email. If it appears, your record is in this leak.
  2. Treat unsolicited calls as hostile. Anyone calling about your Angel One account, KYC update, or a “suspicious transaction” should be verified by calling Angel One’s official number yourself.
  3. Freeze or monitor your credit. In India, request your CIBIL report and watch for unfamiliar inquiries or new accounts. Consider a credit freeze with the bureaus.
  4. Change your Angel One password and enable 2FA. Even though credentials were not leaked here, reuse from other breaches puts your trading account at risk.
  5. Watch for PAN-based fraud. Consider a monitored PAN alert through the Income Tax portal and be wary of any email citing your PAN or portfolio.
  6. Never confirm bank details to inbound callers. Your account number is already known to attackers; do not verify it to anyone.

Industry Context

This is the second major Indian brokerage data incident in recent memory, following similar leaks at other retail trading platforms. Indian financial regulators have been slow to mandate breach disclosure timelines, which is why this April 2023 intrusion only became widely known in mid-2024. Affected users deserve a faster, more transparent process, and the sector deserves stronger data-minimization rules.

Security Insight

The most damaging detail here is not the email list, it is that a stock broker was storing customer PANs, bank account numbers, and portfolio values in the same database that leaked. Under India’s data protection framework, that kind of PII clustering creates a single point of failure with catastrophic blast radius. The 15-month disclosure delay also suggests the company either did not detect the intrusion or chose not to disclose it promptly, both of which are failures of incident response. Brokers that hold this data should be encrypting, tokenizing, and segmenting it, not co-locating it with marketing contact records.

Further Reading

Share:

Never miss a data breach report

Get real-time security alerts delivered to your preferred platform.

Related Breach Reports

Never Miss a Critical Alert

CVE advisories, breach reports, and threat intel — delivered daily to your inbox.