The cyber work behind CashlessConsumer
Open investigations into India's financial infrastructure: the leaks, exposures and registry blind-spots that institutions — and the people who depend on them — deserve to see. Every scan read-only, every finding disclosed responsibly, no consumer PII ever republished.
.bank.in security audit
The Indian financial namespace, mapped: 4,199 subdomains probed daily for resolution, HTTPS and exposure — plus the IDRBT registry investigation.
Bank of Baroda breach
Independently verified the July 2026 Triple X dump at metadata level: 162K files, 1,088+ impacted branches. Full consumer investigation on the dedicated site.
CERT-In · .env exposures
Production .env files served in plain sight on licensed banks' domains — reported to CERT-In and RBI, tracked to remediation.