设为首页加入收藏
  • 首页
  • Start up
  • 当前位置:首页 >Start up >【】

    【】

    发布时间:2025-09-13 03:12:32 来源:都市天下脉观察 作者:Start up

    Latest

    AI

    Amazon

    Apps

    Biotech & Health

    Climate

    Cloud Computing

    Commerce

    Crypto

    Enterprise

    EVs

    Fintech

    Fundraising

    Gadgets

    Gaming

    Google

    Government & Policy

    Hardware

    Instagram

    Layoffs

    Media & Entertainment

    Meta

    Microsoft

    Privacy

    Robotics

    Security

    Social

    Space

    Startups

    TikTok

    Transportation

    Venture

    More from TechCrunch

    Staff

    Events

    Startup Battlefield

    StrictlyVC

    Newsletters

    Podcasts

    Videos

    Partner Content

    TechCrunch Brand Studio

    Crunchboard

    Contact Us

    Byjus signboard at one of its tution center
    Image Credits:Indranil Aditya/Bloomberg / Getty Images
    Security

    Byju’s exposed sensitive student data, including loan details

    Jagmeet Singh 6:50 AM PDT · August 25, 2023

    Byju’s, the edtech giant and India’s most valuable startup, has fixed a server-side misconfiguration that was exposing sensitive data of its students.

    The Indian startup exposed some students’ names, phone numbers, addresses and email IDs. The exposed data also included loan details such as payouts, links to scanned documents and transactional information related to some students.

    Security researcher Bob Diachenko found the exposure due to a misconfigured Apache Kafka server used by Byju’s to send and receive data in real time. Diachenko told TechCrunch that there were several IP addresses with the misconfigured server, which enabled anyone to access the queue to read the records without a password.

    “Anyone could have connected to the queue and read or download the messages,” the researcher told TechCrunch.

    The data was first found to be exposed on August 15, according to Shodan, a search engine for exposed devices and databases.

    While the exact number of students whose data was exposed is unclear, Diachenko said one to two million records were accessible due to the issue.

    Diachenko reported the issue to Byju’s directly on August 22. The misconfiguration was fixed soon after the researcher posted its details on X, the platform formerly known as Twitter, a day later.

    Techcrunch event

    Join 10k+ tech and VC leaders for growth and connections at Disrupt 2025

    Netflix, Box, a16z, ElevenLabs, Wayve, Sequoia Capital, Elad Gil — just some of the 250+ heavy hitters leading 200+ sessions designed to deliver the insights that fuel startup growth and sharpen your edge. Don’t miss the 20th anniversary of TechCrunch, and a chance to learn from the top voices in tech. Grab your ticket before Sept 26 to save up to $668.

    Join 10k+ tech and VC leaders for growth and connections at Disrupt 2025

    Netflix, Box, a16z, ElevenLabs, Wayve, Sequoia Capital, Elad Gil — just some of the 250+ heavy hitters leading 200+ sessions designed to deliver the insights that fuel startup growth and sharpen your edge. Don’t miss the 20th anniversary of TechCrunch, and a chance to learn from the top voices in tech. Grab your ticket before Sept 26 to save up to $668.

    San Francisco | October 27-29, 2025 REGISTER NOW

    Byju’s confirmed to TechCrunch it had fixed the security lapse but claimed “no data or information was exposed or compromised” during the week that the servers were exposed.

    “There was a temporary exposure of a small fraction of our systems for a very short duration,” said Anil Goel, Byju’s chief technology officer, in a prepared statement. “Our technical team has promptly resolved this issue as soon as it came to our notice. We would like to reiterate that all our systems have been built around safeguarding the privacy and security of our data.”

    Byju’s did not confirm the exact number of students affected and did not respond to a question regarding whether the company had notified students of the lapse. Byju’s also would not say if it had the technical means to determine what data, if any, was accessed, and by whom.

    TechCrunch informed India’s computer emergency response team CERT-In about the incident after receiving details from the researcher.

    In June 2021, a server-side issue affecting Byju’s third-party service provider Salesken.ai exposed student data, including the personal details about what classes students were taking through the startup’s online coding platform WhiteHatJr. Salesken.ai pulled the server offline shortly after TechCrunch reached out to the startup.

    Unlike the previous exposure due to the misconfiguration in a Salesken.ai server, the latest issue specifically affects Byju’s infrastructure.

    The data exposure added to the woes of Byju’s, a Bengaluru-based startup valued at $22 billion, which is currently grappling with multiple challenges.

    The startup’s three key investors — Peak XV Partners (erstwhile Sequoia Capital India & SEA), Prosus and Chan Zuckerberg Initiative — quit its board in June, a year after it attracted global scrutiny over delaying financial reporting. Prosus, one of the largest investors in Byju’s, said on its exit from board that its reporting and governance structures “did not evolve sufficiently for a company of that scale.” The investment firm also slashed the valuation of the edtech startup to $5.1 billion in June from the $6 billion it had valued until November.

    Earlier this year, Deloitte also made an early exit from Byju’s as its auditor for long delaying its financial statements.

    Additionally, the startup has continued to lay off employees, including up to 1,000 people in June, to reduce costs.

    Moreover, Byju’s saw searches from the Indian anti-money laundering agency at its offices, and reportedly a probe by the country’s corporate affairs ministry and tensions with its lenders on a $1.2 billion term loan — all at the time it was looking to raise more capital after a $250 million round in May.

    Prosus slashes edtech giant Byju’s valuation to $5.1 billion

    • 上一篇:Arcade scores $7.5M seed to make it simple to build a product demo
    • 下一篇:BloomTech, previously Lambda School, cuts half of staff

      相关文章

      • Flush with Series A funding, Daye unwraps the big gynae health mission
      • How to manage third
      • Blobr raises another $5.4 million for its API monetization product
      • StudentFinance nabs $41M to help Europeans upskill for in
      • To win over investors, use growth as your differentiator
      • TechCrunch+ roundup: Optimizing acquisition, parental leave tips, riding the downturn express
      • TechCrunch+ roundup: Advice for laid
      • TechCrunch+ roundup: Ocean tech investor survey, AI and PR, L
      • Despite myriad flaws, US remains top spot for Black startup founders seeking VC dollars
      • Apply now to speak at TechCrunch Disrupt in September

        随便看看

      • 5 questions for venture capital in Q3 2022
      • On the journey to Series B, strategy is more important than metrics
      • Free Agency CEO seems to care more about control than the company, former employees say
      • Today's TechCrunch Live: Why cybersecurity is still hiring and spending with Vanta and Sequoia
      • Nudge Security emerges from stealth to tackle cybersecurity’s people problem
      • Everything you know about computer vision may soon be wrong
      • Cleantech Qotto embarks on growth plan backed by $8M funding
      • Announcing the TechCrunch Early Stage Audience Choice winners
      • Daily Crunch: Sequoia Capital writes off its $210M investment in crypto exchange FTX
      • This UK startup has come up with a unique way to verify small businesses on WhatsApp
      • Copyright © 2025 Powered by 【】,都市天下脉观察   辽ICP备198741324484号sitemap