LazyPay Security Flaw, Now Fixed, Could Have Been Used to Acquire Sensitive User Information

LazyPay parent PayU fixed the issue quickly after it was reported by a security researcher.

Advertisement
By Jagmeet Singh | Updated: 16 June 2021 15:15 IST
Highlights
  • LazyPay security flaw was found by a security researcher
  • It could have allowed attackers to steal user data from a vulnerable API
  • LazyPay parent PayU quickly responded and fixed the flaw

LazyPay is one of the popular “buy now, pay later” platforms in India

LazyPay, the digital credit platform by Netherlands-based fintech company PayU, was found to have a security flaw that could have allowed hackers to obtain user data such as their full name, gender, date of birth, and phone number, according to a security researcher. He said that the issue was resolved quickly after it was reported to PayU, and the company confirmed the vulnerability but told Gadgets 360 that there was no user data leaked. However, LazyPay has not informed its users about the flaw and its fix.

Bengaluru-based Ehraz Ahmed discovered the vulnerability in LazyPay. He stated that the flaw allowed attackers to fetch sensitive user information by using the phone number of any registered users on the platform.

Upon getting the phone number, an attacker could get data such as the full name, gender, date of birth, postal address, profile picture, primary and secondary email addresses, and know-your-customer (KYC) status, Ahmed explained in a blog post.

Advertisement

He added that the issue was vulnerable as a hacker with minimal programming skills could easily create a program to fetch a series of phone numbers and pass them to the unsecured API to extract sensitive user information in an automated way. The researcher told Gadgets 360 that he found the flaw by tricking one of the API endpoints provided by LazyPay to third-party developers.

Advertisement

Shortly after finding the vulnerability in October, Ahmed reached out to LazyPay parent PayU. The company acknowledged the issue and responsibly fixed it right away. Ahmed reached out to Gadgets 360 with the details about the flaw in late May. After understanding the issue, we communicated with PayU to get further clarity on the matter.

A PayU spokesperson the flaw and also assured Gadgets 360 that its fix was already in place.

Advertisement

“PayU takes the security of our systems and our data very seriously,” the spokesperson said. “We are continuously running checks to ensure that our payment systems are safe and secure for everyone to access and use. The incident with regard to the security gap with LazyPay which was reported in the month of October was immediately resolved. There was no leak of customer information due to this incident.”

The company, however, did not inform its customers directly about the incident that had put their personal data at risk.

Advertisement

Launched back in 2017, LazyPay comes as a “buy now, pay later” offering by PayU to let customers make repayments for their orders online via instalments. The platform is claimed to be accepted across over 250 websites and apps, including BookMyShow, Flipkart, MakeMyTrip, and Swiggy.

LazyPay also offers personal loans up to Rs. 1 lakh through a digital process. Customers signing up on the platform are required to provide their photo ID proofs such as PAN or Aadhaar, alongside their bank details, and a selfie.


Interested in cryptocurrency? We discuss all things crypto with WazirX CEO Nischal Shetty and WeekendInvesting founder Alok Jain on Orbital, the Gadgets 360 podcast. Orbital is available on Apple Podcasts, Google Podcasts, Spotify, Amazon Music and wherever you get your podcasts.
Affiliate links may be automatically generated - see our ethics statement for details.
 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Further reading: LazyPay, PayU, security flaw
Advertisement

Related Stories

Popular Mobile Brands
  1. Moto Pad 60 Neo India Launch Date, Key Features, Availability Confirmed
  2. Motorola Edge 60 Pro Review: Quite the Performer
  3. Oppo F31 Series to Launch in India on September 15: All You Need to Know
  4. These Poco Phones Will Be Discounted During the Flipkart Big Billion Days
  5. Xiaomi 15T Series Will Launch With Leica-Tuned Cameras on This Date
  6. iPhone 17 Air, Apple's Slimmest Phone: What to Expect
  7. Coolie OTT Release Date is Confirmed: All You Need to Know
  8. Here's When Your Samsung Galaxy Device Might Get the One UI 8 Update
  9. Honor Play 10 With MediaTek Helio G81 SoC Launched: Report
  1. Exoplanets Explained: How Astronomers Find Worlds Orbiting Stars Beyond the Sun
  2. sPHENIX Detector Clears Test to Study Quark-Gluon Plasma Which Formed After the Big Bang, Claims Study
  3. UY Scuti Reigns as the Universe’s Biggest Known Star, but Its Crown May Be at Risk
  4. Legion Legion Go 2 Will Get ROG Xbox Ally's New Full-Screen Xbox Interface Next Year
  5. Google Nest Cam Outdoor and Indoor Models, Nest Doorbell With Gemini AI Spotted in a Retail Store
  6. Param Sundari OTT Release: When and Where to Watch Janhvi Kapoor-Starrer Online?
  7. Bitcoin’s Largest Whale Dump Since 2022: A Cause for Concern or Just Market Noise?
  8. Coolie OTT Release Date Confirmed: Know When and Where to Watch the Rajinikanth-Starrer Online
  9. Nothing Ear 3 Launch Date Announced; Design Partially Teased Ahead of Debut
  10. Dragon Ball Z Season 3 To Premiere on Netflix in September: All You Need to Know About This Popular Japanese Anime
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.