All UPI IDs in India have Predictable Patterns that allow the disclosure of mail IDs!

4 hours ago 5
BOOK THIS SPACE FOR AD
ARTICLE AD

JEETPAL

Read Free

Hey, security enthusiasts! 🌟 As UPI (Unified Payments Interface) dominates the Indian digital payments landscape, I noticed a privacy loophole across all major UPI platforms that could expose sensitive user information. This isn’t just about UPI apps — it’s a systemic issue! 🛑

Let’s break it down step by step. 🕵️‍♂️💻

UPI IDs are generated based on your email address or phone number. Most platforms like PhonePe, Google Pay, Paytm, and others follow similar patterns:

Email-Based UPI IDsIf your email is pal6504@gmail.com, your UPI ID becomes:
👉 pal6504@oksbi,pal6504@okaxis, or pal6504@okhdfcbank (depending on your bank).

2. Phone Number-Based UPI IDs

If your phone number is 9876543210, your UPI ID becomes:
👉 9876543210@oksbi, 9876543210@okicici, etc.

3. Multiple Accounts with the Same Email

Platforms handle this by using incremental IDs:First account → pal6504@oksbiSecond account → pal6504–1@oksbiThird account → pal6504–2@oksbiThis predictable system makes UPI IDs convenient, but also creates major privacy risks.
Read Entire Article