Home / Data breaches / Upstox

Data breach · 2021

The Upstox data breach, explained

Upstox (upstox.com) was breached on April 8, 2021, exposing 111 thousand accounts, passwords included. Here is exactly what leaked, what it means, and the order to fix things in.

111,002 accounts · 13 data classes · verified record

The numbers

What the record shows

111,002accounts in the breach
April 8, 2021date of the breach
January 19, 2022publicly indexed
~9 monthsbetween breach and public disclosure, while the data circulated and nobody knew to reset anything

What leaked

13 kinds of data were exposed

Bank account numbers
Dates of birth

A permanent identifier you cannot rotate, and a common identity-verification answer.

Email addresses

The universal account key. Exposed addresses get targeted with credential-stuffing and phishing that name the breached site to look legitimate.

Family members' names
Genders

Profile data that sharpens targeted phishing.

Government issued IDs
Income levels
Marital statuses
Nationalities
Occupations
Passwords

The one that matters most. Even hashed passwords get cracked at scale, and every account where this password was reused is now reachable.

Phone numbers

Enables SIM-swap attempts and smishing, and links this account to every other one that knows the number.

Physical addresses

Where you live. Combined with a name it supports identity fraud and very convincing postal or doorstep scams.

In this order

What to do now

  1. Reset the Upstox password first

    Use the official forgot-password flow on upstox.com directly, never a link from an email about the breach; breach news is prime phishing bait.

  2. Kill the reuse, which is the real damage

    Every account sharing the exposed password is now one automated attempt from gone. This is the tedious part, and it is the part Repass automates: it finds the accounts and runs each site's official reset flow for you.

  3. Scan your email for the rest of your exposure

    Run the free breach scan on the address you use most. Upstox is one breach; the median active email address appears in several, and what to fix first depends on the full picture.

  4. Turn on two-factor authentication

    A leaked password with a second factor in front of it is a locked door with a stolen key that no longer fits. Prefer an authenticator app over texted codes where the service offers the choice.

Questions

Upstox breach FAQ

Was my Upstox account affected by the breach?

The record covers 111,002 accounts. The quick way to check is a breach scan against your own email address, which searches this breach and hundreds of others at once. Repass runs one free on its homepage.

What should I change first after the Upstox breach?

The Upstox password itself, immediately. Then every other account where you used the same or a similar password, because that reuse is what attackers actually exploit.

Is changing my Upstox password enough?

Only if that password lived nowhere else. Credential-stuffing takes leaked email-and-password pairs and tries them on banks, mailboxes and stores at machine speed, so the reused copies matter more than the original. A reused password is a breach of every account that shares it.

Where does this breach data come from?

From the public index maintained by Have I Been Pwned, which verifies breaches before listing them. This page renders the structured record: dates, account count and exposed data classes.

How do I find out what else has leaked about me?

Run a breach scan on your email address. It returns every verified breach that lists the address, which is the honest starting point for deciding what to reset first. Repass then resets the passwords for you, one official flow at a time, and seals each new one in an encrypted vault.

Source: the verified Upstox record at Have I Been Pwned · attribution: white_peacock@riseup.net. Checked against the index of 2026-08-20.

After the breach

Every reused password, replaced for you.

Get Started

3-day free trial · strong unique passwords · encrypted vault

Reset your passwordsRepass does it for you, free for 3 days Get Started