设为首页加入收藏
  • 首页
  • Start up
  • 当前位置:首页 >Start up >【】

    【】

    发布时间:2025-09-21 00:11:48 来源:都市天下脉观察 作者:Start up

    Latest

    AI

    Amazon

    Apps

    Biotech & Health

    Climate

    Cloud Computing

    Commerce

    Crypto

    Enterprise

    EVs

    Fintech

    Fundraising

    Gadgets

    Gaming

    Google

    Government & Policy

    Hardware

    Instagram

    Layoffs

    Media & Entertainment

    Meta

    Microsoft

    Privacy

    Robotics

    Security

    Social

    Space

    Startups

    TikTok

    Transportation

    Venture

    More from TechCrunch

    Staff

    Events

    Startup Battlefield

    StrictlyVC

    Newsletters

    Podcasts

    Videos

    Partner Content

    TechCrunch Brand Studio

    Crunchboard

    Contact Us

    Byjus signboard at one of its tution center
    Image Credits:Indranil Aditya/Bloomberg / Getty Images
    Security

    Byju’s exposed sensitive student data, including loan details

    Jagmeet Singh 6:50 AM PDT · August 25, 2023

    Byju’s, the edtech giant and India’s most valuable startup, has fixed a server-side misconfiguration that was exposing sensitive data of its students.

    The Indian startup exposed some students’ names, phone numbers, addresses and email IDs. The exposed data also included loan details such as payouts, links to scanned documents and transactional information related to some students.

    Security researcher Bob Diachenko found the exposure due to a misconfigured Apache Kafka server used by Byju’s to send and receive data in real time. Diachenko told TechCrunch that there were several IP addresses with the misconfigured server, which enabled anyone to access the queue to read the records without a password.

    “Anyone could have connected to the queue and read or download the messages,” the researcher told TechCrunch.

    The data was first found to be exposed on August 15, according to Shodan, a search engine for exposed devices and databases.

    While the exact number of students whose data was exposed is unclear, Diachenko said one to two million records were accessible due to the issue.

    Diachenko reported the issue to Byju’s directly on August 22. The misconfiguration was fixed soon after the researcher posted its details on X, the platform formerly known as Twitter, a day later.

    Techcrunch event

    Join 10k+ tech and VC leaders for growth and connections at Disrupt 2025

    Netflix, Box, a16z, ElevenLabs, Wayve, Sequoia Capital, Elad Gil — just some of the 250+ heavy hitters leading 200+ sessions designed to deliver the insights that fuel startup growth and sharpen your edge. Don’t miss the 20th anniversary of TechCrunch, and a chance to learn from the top voices in tech. Grab your ticket before Sept 26 to save up to $668.

    Join 10k+ tech and VC leaders for growth and connections at Disrupt 2025

    Netflix, Box, a16z, ElevenLabs, Wayve, Sequoia Capital, Elad Gil — just some of the 250+ heavy hitters leading 200+ sessions designed to deliver the insights that fuel startup growth and sharpen your edge. Don’t miss the 20th anniversary of TechCrunch, and a chance to learn from the top voices in tech. Grab your ticket before Sept 26 to save up to $668.

    San Francisco | October 27-29, 2025 REGISTER NOW

    Byju’s confirmed to TechCrunch it had fixed the security lapse but claimed “no data or information was exposed or compromised” during the week that the servers were exposed.

    “There was a temporary exposure of a small fraction of our systems for a very short duration,” said Anil Goel, Byju’s chief technology officer, in a prepared statement. “Our technical team has promptly resolved this issue as soon as it came to our notice. We would like to reiterate that all our systems have been built around safeguarding the privacy and security of our data.”

    Byju’s did not confirm the exact number of students affected and did not respond to a question regarding whether the company had notified students of the lapse. Byju’s also would not say if it had the technical means to determine what data, if any, was accessed, and by whom.

    TechCrunch informed India’s computer emergency response team CERT-In about the incident after receiving details from the researcher.

    In June 2021, a server-side issue affecting Byju’s third-party service provider Salesken.ai exposed student data, including the personal details about what classes students were taking through the startup’s online coding platform WhiteHatJr. Salesken.ai pulled the server offline shortly after TechCrunch reached out to the startup.

    Unlike the previous exposure due to the misconfiguration in a Salesken.ai server, the latest issue specifically affects Byju’s infrastructure.

    The data exposure added to the woes of Byju’s, a Bengaluru-based startup valued at $22 billion, which is currently grappling with multiple challenges.

    The startup’s three key investors — Peak XV Partners (erstwhile Sequoia Capital India & SEA), Prosus and Chan Zuckerberg Initiative — quit its board in June, a year after it attracted global scrutiny over delaying financial reporting. Prosus, one of the largest investors in Byju’s, said on its exit from board that its reporting and governance structures “did not evolve sufficiently for a company of that scale.” The investment firm also slashed the valuation of the edtech startup to $5.1 billion in June from the $6 billion it had valued until November.

    Earlier this year, Deloitte also made an early exit from Byju’s as its auditor for long delaying its financial statements.

    Additionally, the startup has continued to lay off employees, including up to 1,000 people in June, to reduce costs.

    Moreover, Byju’s saw searches from the Indian anti-money laundering agency at its offices, and reportedly a probe by the country’s corporate affairs ministry and tensions with its lenders on a $1.2 billion term loan — all at the time it was looking to raise more capital after a $250 million round in May.

    Prosus slashes edtech giant Byju’s valuation to $5.1 billion

    • 上一篇:Google opens applications for circular
    • 下一篇:A flat year for crowdfunding isn't a bad sign at all for early

      相关文章

      • Daily Crunch: High
      • Just 48 hours left to save $800 on passes to Disrupt
      • How much does your company pollute? CarbonChain gets $10M Series A to help answer that
      • 'Amex
      • Track and capture: Getting started with attention metrics
      • Meet Visa, Mayfield, DuploCloud and more at Disrupt
      • Warm intros are awful for diversity, so why do investors keep insisting on them?
      • Energy Dome gets $44M uplift into its CO2 battery for renewable energy storage
      • 2023 will be the year of cyber
      • Vote for the roundtables and breakouts you want at Disrupt

        随便看看

      • Former VC brings smart financial advice to people who really need it, instead of just the rich
      • A pivot, in this market‽
      • TechCrunch Live is (virtually) going to Atlanta and you're invited!
      • 8fig gives smaller e
      • Meeting camera startup Owl Labs lands $25M and partnership with HP
      • Precision fermentation’s capacity craze: Have we lost the plot?
      • Ask Sophie: Can I apply for an EB
      • Pietra helped creators start DTC businesses; now it has a roadmap for everyone
      • 2023 will be the year of cyber
      • Ryan Breslow’s Love health, wellness marketplace goes live
      • Copyright © 2025 Powered by 【】,都市天下脉观察   辽ICP备198741324484号sitemap