Angel One: 6.8M Users Exposed in Broker Data Breach
In July 2024, the Indian stock brokerage firm Angel One confirmed that data leaked online related to a breach that occurred in April 2023 . The leaked data included 7.9M user records containing 6.8M unique email addresses, along with names, physical addresses, phone numbers, bank account numbers, Pe...
Overview
Angel One, one of India’s largest retail stock brokerages, confirmed in July 2024 that a trove of customer data had surfaced online, tied to an intrusion that actually took place in April 2023. The leaked file contained roughly 7.9 million user records, of which about 6.8 million were unique email addresses. In total, 6,765,054 accounts are confirmed affected.
The disclosure only became public after the data was loaded into Have I Been Pwned, the breach-notification service run by security researcher Troy Hunt. The 15-month gap between the intrusion and confirmation is one of the more troubling details of this case.
Angel One’s official line is that the breach “has no impact on client securities, funds, or credentials.” That may be true for trading accounts directly, but it sidesteps what was actually taken.
What Was Exposed
According to the leaked dataset, the records include:
- Email addresses (6.8 million unique)
- Full names
- Phone numbers
- Physical addresses
- Bank account numbers
- Permanent Account Numbers (PANs) - India’s national tax ID
- Portfolio holdings
Angel One’s statement emphasized securities and credentials were untouched, but it did not dispute the presence of bank account numbers, PANs, or portfolio data in the leak.
Why This Combination Is Dangerous
Individually, an email or phone number is low-value. Combined, this dataset is a turnkey identity-theft kit.
Your PAN is the master key for Indian financial identity. It links to tax filings, loan applications, demat accounts, and KYC records. With a PAN, name, and phone number, fraudsters can attempt to open accounts, file fraudulent returns, or impersonate you with lenders.
Bank account numbers plus a name and phone number are exactly what vishing (voice phishing) scammers need to sound credible. A caller who already knows your bank, your name, and your address is far more convincing than a cold caller.
Portfolio holdings are a profiling goldmine. They tell an attacker how wealthy you are and which brokers or assets you use, making you a better-targeted mark for investment fraud.
What to Do Right Now
- Check Have I Been Pwned. Visit haveibeenpwned.com and search your email. If it appears, your record is in this leak.
- Treat unsolicited calls as hostile. Anyone calling about your Angel One account, KYC update, or a “suspicious transaction” should be verified by calling Angel One’s official number yourself.
- Freeze or monitor your credit. In India, request your CIBIL report and watch for unfamiliar inquiries or new accounts. Consider a credit freeze with the bureaus.
- Change your Angel One password and enable 2FA. Even though credentials were not leaked here, reuse from other breaches puts your trading account at risk.
- Watch for PAN-based fraud. Consider a monitored PAN alert through the Income Tax portal and be wary of any email citing your PAN or portfolio.
- Never confirm bank details to inbound callers. Your account number is already known to attackers; do not verify it to anyone.
Industry Context
This is the second major Indian brokerage data incident in recent memory, following similar leaks at other retail trading platforms. Indian financial regulators have been slow to mandate breach disclosure timelines, which is why this April 2023 intrusion only became widely known in mid-2024. Affected users deserve a faster, more transparent process, and the sector deserves stronger data-minimization rules.
Security Insight
The most damaging detail here is not the email list, it is that a stock broker was storing customer PANs, bank account numbers, and portfolio values in the same database that leaked. Under India’s data protection framework, that kind of PII clustering creates a single point of failure with catastrophic blast radius. The 15-month disclosure delay also suggests the company either did not detect the intrusion or chose not to disclose it promptly, both of which are failures of incident response. Brokers that hold this data should be encrypting, tokenizing, and segmenting it, not co-locating it with marketing contact records.
Further Reading
Never miss a data breach report
Get real-time security alerts delivered to your preferred platform.
Related Breach Reports
In September 2026, Swiss medical device company Medela was the target of a ShinyHunters "pay or leak" extortion campaign . The data allegedly obtained in the breach was later published publicly and included 424k unique email addresses belonging predominantly to healthcare professionals, Medela staff...
In August 2026, the French intellectual property software and services company Questel was the target of a ShinyHunters "pay or leak" extortion campaign . The group subsequently published an extensive corpus of data they alleged was obtained from the company, largely comprising corporate contact inf...
In July 2026, the cloud-based business communications platform RingCentral was the target of a ShinyHunters "pay or leak" extortion campaign . The group subsequently published data they claimed was obtained from the platform, which included 1.6M unique email addresses along with names, physical addr...
In August 2026, the Alcon eye care company was named in a ShinyHunters "pay or leak" extortion campaign . The group subsequently published data allegedly sourced from Alcon containing 218k unique email addresses along with other largely corporate B2B contact fields, including name, phone number and ...