Angel One: 6.8 million customer records surface in breach database, broker silent

Have I Been Pwned has quietly added a three-year-old breach of India's biggest retail broker - but there's still no sign AngelOne has told anyone.

Brown padlock on black computer keyboard
Photo · FlyD / Unsplash

The claim

A dataset tied to Angel One, the Indian trading and investment platform that claims more than 38 million registered users, has turned up in Have I Been Pwned’s breach archive. The listing puts the affected count at 6.8 million accounts, dates the original incident to April 2023, and marks the entry as “verified” - HIBP’s term for data it has independently checked looks genuine, not a confirmation that Angel One has acknowledged anything.

The categories of data listed are the sort that matter: names, dates of birth, phone numbers, physical addresses, email addresses, government-issued ID numbers, bank account numbers and details of financial investments. That’s a markedly heavier haul than a typical “email and password” leak - it’s the kind of information that, in the wrong hands, can be stitched together for identity fraud or used to make phishing attempts look convincingly official.

What’s actually known versus what isn’t

Here’s the catch. HIBP’s “verified” tag tells you the researchers behind the database believe the leaked records are real and match a real population of users - it is not a statement from Angel One confirming a breach, naming a cause, or saying how the data got out. As of writing, angelone.in carries no visible breach notice, security advisory or customer communication referencing an incident from April 2023.

That three-year gap between the alleged breach date and the data appearing in HIBP is also worth noting. It means that if this data is genuine, it has potentially been circulating - quietly, or on criminal marketplaces - for a long time before becoming public knowledge via a breach-notification service. Whether Indian regulators, such as SEBI or the data protection authorities, were ever informed at the time is not addressed by the available sources.

So who is actually at risk

If you are, or have been, an Angel One customer, this listing means a 2023-era snapshot of your personal and possibly financial details may be in circulation - but there’s no confirmation yet of the exact scope, how the breach happened, or whether it has already been exploited. Nobody outside Angel One’s user base is affected, and having a demat account with a different broker tells you nothing either way.

It’s also not yet clear whether the “bank account numbers” field refers to full account details or partial/masked references, which materially changes the risk. HIBP’s public listing doesn’t go that far into specifics, and Angel One hasn’t - at least publicly - filled in the gaps.

What to do about it

Angel One account holders should treat this as a prompt rather than a verdict: check your account activity, be wary of emails or calls claiming to be from the broker that ask you to “verify” details, and consider changing your login password and enabling two-factor authentication if you haven’t already. You can check whether your own email address appears in the listing via Have I Been Pwned.

The takeaway

A breach entry appearing on HIBP is a solid technical signal, but it isn’t the same as a company owning up to what happened. Until Angel One says something concrete about what occurred in April 2023 - if anything - this is best filed under “watch this space” rather than “panic now.”

Sources