This page documents a data breach listing tracked by Breach House. It summarizes the
publicly advertised leak attributed to Database World ROC,
including the affected entity, origin and the date the listing was first indexed.
Breach Overview
In April 2021, Indian brokerage firm Upstox suffered a data breach. The incident exposed extensive personal information on over 100k customers including names, genders, dates of birth, physical addresses, banking information and passwords stored as bcrypt hashes. Extensive "know your customer" information was also exposed including scans of bank statements, cheques and identity documents complete with Aadhaar numbers. Compromised data: Bank account numbers, Dates of birth, Email addresses, Family members names, Genders, Government issued IDs, Income levels, Marital statuses, Nationalities, Occupations, Passwords, Phone numbers, Physical addresses
Dark Web Exposure
Findings for upstox.com
— indexed by HaveIBeenRansom.
71,010
found in Infostealer logs
4,795+
found in Traditional breaches
2+
found in Ransomware leaks
Upstox_BF.7z
B F R e p o V 3 F i l e s · breach
••• emails
upstox.com_Database.zip
Database World ROC · breach
••• emails
limeleads_breach.7z
TheUnderground - Reborn · breach
••• emails
@BreachedData1 LinkedIn 2021-23 Cleaned.7z.001
Database World ROC · breach
••• emails
pureincubation-com.7z.001
Database World ROC · breach
••• emails
Database World ROC · breach
••• emails
B F R e p o V 3 F i l e s · breach
••• emails
+ 5 more leak sources locked
Leak volumes are locked
Sign in to reveal how many records each source exposed and the remaining 8 sources.
Legal Disclaimer:
This breach record is compiled from publicly advertised leak listings.
Breach.house only records what the operators themselves publish in the
open. We take screenshots of their public pages and keep the proof
material they post there, so that a listing can be verified and its status
tracked over time. We do not purchase data, we do not solicit or encourage
its publication, we do not access any private system, and we do not alter
anything we record. Nothing is offered for download here, and detailed
content is not published on this page or anywhere else on the public site:
access to it is restricted to vetted customers under contract, for
incident response, due diligence and cyber-resilience work.
Breach.house is not affiliated with, and does not act on behalf of, the
operators who publish this material. If you represent an organisation or
individual named here and want a record reviewed or removed, contact us
and we will act on it.