LazyPay Security Flaw, Now Fixed, Could Have Been Used to Acquire Sensitive User Information

LazyPay parent PayU fixed the issue quickly after it was reported by a security researcher.

Advertisement
By Jagmeet Singh | Updated: 16 June 2021 15:15 IST
Highlights
  • LazyPay security flaw was found by a security researcher
  • It could have allowed attackers to steal user data from a vulnerable API
  • LazyPay parent PayU quickly responded and fixed the flaw

LazyPay is one of the popular “buy now, pay later” platforms in India

LazyPay, the digital credit platform by Netherlands-based fintech company PayU, was found to have a security flaw that could have allowed hackers to obtain user data such as their full name, gender, date of birth, and phone number, according to a security researcher. He said that the issue was resolved quickly after it was reported to PayU, and the company confirmed the vulnerability but told Gadgets 360 that there was no user data leaked. However, LazyPay has not informed its users about the flaw and its fix.

Bengaluru-based Ehraz Ahmed discovered the vulnerability in LazyPay. He stated that the flaw allowed attackers to fetch sensitive user information by using the phone number of any registered users on the platform.

Upon getting the phone number, an attacker could get data such as the full name, gender, date of birth, postal address, profile picture, primary and secondary email addresses, and know-your-customer (KYC) status, Ahmed explained in a blog post.

Advertisement

He added that the issue was vulnerable as a hacker with minimal programming skills could easily create a program to fetch a series of phone numbers and pass them to the unsecured API to extract sensitive user information in an automated way. The researcher told Gadgets 360 that he found the flaw by tricking one of the API endpoints provided by LazyPay to third-party developers.

Advertisement

Shortly after finding the vulnerability in October, Ahmed reached out to LazyPay parent PayU. The company acknowledged the issue and responsibly fixed it right away. Ahmed reached out to Gadgets 360 with the details about the flaw in late May. After understanding the issue, we communicated with PayU to get further clarity on the matter.

A PayU spokesperson the flaw and also assured Gadgets 360 that its fix was already in place.

Advertisement

“PayU takes the security of our systems and our data very seriously,” the spokesperson said. “We are continuously running checks to ensure that our payment systems are safe and secure for everyone to access and use. The incident with regard to the security gap with LazyPay which was reported in the month of October was immediately resolved. There was no leak of customer information due to this incident.”

The company, however, did not inform its customers directly about the incident that had put their personal data at risk.

Advertisement

Launched back in 2017, LazyPay comes as a “buy now, pay later” offering by PayU to let customers make repayments for their orders online via instalments. The platform is claimed to be accepted across over 250 websites and apps, including BookMyShow, Flipkart, MakeMyTrip, and Swiggy.

LazyPay also offers personal loans up to Rs. 1 lakh through a digital process. Customers signing up on the platform are required to provide their photo ID proofs such as PAN or Aadhaar, alongside their bank details, and a selfie.


Interested in cryptocurrency? We discuss all things crypto with WazirX CEO Nischal Shetty and WeekendInvesting founder Alok Jain on Orbital, the Gadgets 360 podcast. Orbital is available on Apple Podcasts, Google Podcasts, Spotify, Amazon Music and wherever you get your podcasts.
Affiliate links may be automatically generated - see our ethics statement for details.
 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: LazyPay, PayU, security flaw
Advertisement

Related Stories

Popular Mobile Brands
  1. iQOO Neo 11 With Snapdragon 8 Elite SoC Launched: Price, Specifications
  2. Top OTT Releases of the Week: Kantara Chapter 1, Lokah Chapter 1, Idli Kadai, and More
  3. Vivo X300 Series Launching Today: Everything You Need to Know
  4. Gemini 3 AI Model Will Be Released Soon, Says Google CEO Sundar Pichai
  5. Reliance Offers Free 18-Month Google AI Pro with Gemini, Veo to Jio Users
  6. Nothing Phone 3a Lite Launched With Glyph Light At This Price
  7. Microsoft Azure Outage: What Caused the Issue, How It Was Resolved
  8. Realme GT 8 Pro Will Launch in India in November With This Chipset
  9. Meta's VR Headsets and AI Glasses Cost the Company $4.4 Billion
  10. Samsung Galaxy S26 Series Teased to Launch With These Notable Upgrades
  1. Reliance Users to Get Free Google AI Pro Access for 18 Months Worth Rs. 35,100 With Gemini, Veo Features
  2. Meta’s VR Headsets and AI Glasses Cost the Company $4.4 Billion in Q3 2025
  3. iQOO Neo 11 With 7,500mAh Battery, Snapdragon 8 Elite Chip Launched: Price, Specifications
  4. Telegram Founder Pavel Durov Launches Cocoon, a Decentralised AI Project on TON
  5. Hedda (2025) Now Available for Streaming on Amazon Prime Video: What You Need to Know
  6. Samsung Galaxy S26 Series Teased to Launch With Upgraded Chipset, Camera, and AI Features
  7. Snapdragon 8 Gen 5 Chipset Key Specifications and Benchmark Scores Tipped; May Power Upcoming iQOO, Vivo Phones
  8. Realme GT 8 Pro Confirmed to Launch in India in November; Will Go on Sale via Flipkart
  9. Samsung Wallet Updated With UPI Onboarding and Support for Biometric Payments
  10. OpenAI Lays Groundwork for Juggernaut IPO at Up to $1 Trillion Valuation
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.