Posts

Showing posts from August, 2026

What Happens When Your Email Is Used as a “Forgot Password” Recovery Point You Didn’t Expect

TL;DR: Most people set a recovery email once and forget about it — but that recovery point often becomes the single most powerful key to dozens of accounts you signed up for years ago. If that recovery email is old, shared, or itself compromised, it's a silent risk sitting underneath your entire digital identity. Here's how to audit it. Every account you've ever created has a recovery mechanism attached — usually an email address, sometimes a phone number. Over years of signing up for services, that recovery chain quietly accumulates, and most people have never actually traced where it leads. Why This Matters More Than It Seems A single email address is often the recovery point for far more accounts than most people realise — social media, shopping accounts, old forums, subscription services, sometimes even financial platforms. If that email is compromised, or if it's an old account you no longer actively monitor, an attacker doesn't need to breach each indiv...

How Loan Apps in India Collect and Misuse Personal Data

TL;DR: Unregulated instant-loan apps have built a well-documented playbook: request excessive permissions at install, extract a tiny loan, then use your contact list and photos to harass you and everyone you know when repayment terms turn predatory. Here's how the data misuse actually works and how to check if a lending app is legitimate. India has seen a genuine crackdown on fraudulent loan apps, with the RBI removing large numbers of unauthorised lending apps from Indian app stores. Understanding the data-misuse mechanism — not just the financial scam — is key to recognising the risk before installing anything. The Data These Apps Request — and Why It's a Red Flag Legitimate, RBI-regulated lenders typically need minimal data beyond standard KYC and a camera permission for a verification selfie. Fraudulent loan apps, by contrast, routinely request: Full contact list access — the single most important permission for their business model, since it becomes the harassme...

What Data Do Health and Fitness Apps in India Collect, and Where Does It Go?

TL;DR: Health and fitness apps — from gym and workout apps to diagnostic and telemedicine platforms — collect some of the most sensitive personal data that exists: biometric readings, medical history, menstrual cycle data, and behavioural patterns. Here's what's actually gathered, how India's health data framework treats it, and what to check before you share it. Fitness and health apps have become a normal part of daily life for many Indians — workout trackers, diet apps, telemedicine platforms, and diagnostic services. What's less visible is just how sensitive the underlying data is, and how differently it's treated compared to, say, a shopping app. What These Apps Actually Collect Biometric and physiological data — heart rate, sleep patterns, step count, sometimes blood glucose or other health metrics from connected wearables Medical history — conditions, medications, and consultation notes on telemedicine and diagnostic platforms Location data — wor...

Setting Up Passkeys and Authenticator Apps: A Step-by-Step Guide for Your Main Accounts

TL;DR: Knowing you should move beyond SMS-only authentication is one thing — actually setting it up is another. This is a practical, account-by-account walkthrough for setting up authenticator apps and passkeys on the accounts that matter most: email, banking-adjacent logins, and major platforms. Once you understand why SMS-only 2FA has gaps, the next question is simply: how do I actually turn on something stronger? Here's the practical setup process, starting with the accounts worth prioritising. Where to Start: Prioritise by Impact Not every account needs the same level of protection immediately. Start with: Your primary email — because it's usually the recovery point for everything else Banking and UPI apps that support app-based or biometric authentication Any account tied to your professional identity — LinkedIn, work email, cloud storage Setting Up an Authenticator App Google Authenticator, Microsoft Authenticator, and Authy are the most widely used optio...

Digital Arrest Scams in India: How They Work and What Personal Data Makes Them Convincing

TL;DR: "Digital arrest" is not a real legal process anywhere in Indian law — but the scam built around that fake premise has caused massive financial losses across India. Fraudsters impersonate police, CBI, ED, or RBI officials over video call, using real personal details to make the threat feel credible. Here's exactly how it works and what information makes it convincing. Digital arrest scams have become one of the fastest-growing categories of cyber fraud in India, with cumulative losses reported in the thousands of crores over the past two years. Understanding the mechanism — and specifically what personal data scammers use to make the con work — is the most effective defence. How the Scam Typically Unfolds The pattern is consistent across most reported cases: The initial contact — a call or message claiming to be from a courier company (often referencing a parcel supposedly containing drugs, fake passports, or illegal SIM cards), a telecom operator, or dir...

Two-Factor Authentication and Account Recovery: Closing the Gaps Attackers Actually Use

TL;DR: Most people set up 2FA once and assume they're covered. Attackers don't target the 2FA itself — they target the recovery process around it: SIM swaps, weak security questions, and outdated backup emails. This guide covers where the real gaps are and how to close them, including India's shift away from SMS-only authentication. Why SMS-Based 2FA Alone Is No Longer Considered Sufficient SMS one-time passwords have been the default second factor in India for years, largely because they require no extra app and work on any phone. The weakness is structural: SMS OTPs depend on your phone number remaining under your control, and SIM swap fraud specifically targets that dependency. In a SIM swap, a fraudster convinces or bribes a telecom outlet — or exploits weak verification — into porting your number onto a SIM they control. Once that happens, they receive your OTPs directly, and password-reset flows that rely on SMS become a way in, not a safeguard. This risk has...

How Employers Actually Run Background Checks in India

TL;DR: Employer background checks in India typically combine formal verification services with informal online searches — and candidates are often unaware of exactly what gets checked. This article covers the actual mechanics: what recruiters and HR teams commonly verify, what's legally permissible, and what a background check actually surfaces. Most conversations about background checks focus on what a candidate should clean up. This one looks at the other side — how the process actually works from the employer's end, and what that means for what you should expect. What a Formal Background Check Typically Covers Larger companies, particularly in IT, BFSI, and MNC environments, often use third-party verification agencies. A standard check typically includes: Employment history verification — confirming dates, designation, and sometimes salary with previous employers Education verification — confirming degrees and institutions directly with universities or through d...

Aadhaar-Linked Data Leaks: What Happened in Past Incidents and What It Means for You

TL;DR: Aadhaar-linked data has been exposed in several documented incidents over the years — most notably a 2018 exposure and a large 2023 leak connected to ICMR/CoWIN data. This article walks through what's actually been confirmed by researchers and reporting, and what that history means for how you think about your own exposure today. Aadhaar is central to how most Indians interact with government services, banking, and increasingly private-sector verification. Its scale — over 1.4 billion enrolments since 2009 — means that when Aadhaar-linked data is exposed, the numbers involved are often described in hundreds of millions, not thousands. The 2018 Exposure In 2018, researchers and reporting identified vulnerabilities in poorly secured systems — including third-party utility and government-adjacent portals — that allowed unauthorised access to Aadhaar-linked records. Reports at the time estimated the scale at over a billion records, making it one of the most significant id...

What Information Do Food Delivery and Ride-Hailing Apps Actually Collect?

TL;DR: Food delivery and ride-hailing apps are among the most-used apps on Indian smartphones — and among the most data-intensive. Beyond your name and phone number, they routinely collect live location, home and work addresses, payment details, and behavioural patterns. Here's what's actually being gathered and what you can do about it. Swiggy, Zomato, Ola, Uber, Rapido, and similar apps have become part of daily routine for a large number of urban Indians. Their convenience depends on collecting more personal data than most other app categories — location tracking, in particular, is central to how they function, not incidental to it. The Core Data These Apps Collect Precise location — continuously while the app is open, and in many cases in the background, to match riders with drivers or calculate delivery routes Home and work addresses — saved addresses reveal exactly where you live and where you work, often with unit-level precision Phone number and name — requ...

UPI and Payment Apps: How Your Payment History Can Be Used to Track You

TL;DR: Every UPI payment you make links your identity to a Virtual Payment Address (VPA) — and if that VPA is your phone number, every transaction quietly ties your number to a name, a pattern of spending, and a network of people you pay. This isn't about your money being stolen. It's about what your payment history reveals when pieced together. UPI has become the default way most Indians move money — over 50% of digital transactions in the country now happen through it. What's less discussed is that every transaction leaves a trail, and that trail is more revealing than most people realise. What a VPA Actually Reveals A Virtual Payment Address, or VPA, is the unique ID — like name@bank or phonenumber@upi — that UPI uses to route a payment without exposing your actual bank account number. That part is genuinely good for privacy: your account number and IFSC code stay hidden. But the default VPA many people use is their own phone number. That means every merchant,...

The Complete Guide to Matrimony and Dating Privacy in India

TL;DR: Matrimonial and dating platforms in India involve sharing deeply personal information with strangers — sometimes before you have any reason to trust them. This guide covers what you're actually exposing when you create a profile, how to spot fraud early, how to verify someone the right way, what's legal when it comes to background checks, and what to do if something goes wrong. It's the one page you should read before anything else. 1. Why Matrimonial and Dating Privacy Needs Its Own Approach in India Privacy online is a general concern. Matrimonial and dating privacy is a specific one — and the stakes are different. When you sign up for a food delivery app, you share your address. When you join a matrimonial platform, you share your name, age, photo, religion, caste, education, income, family background, city, and in many cases your phone number. That's not a profile. That's a dossier. And you're sharing it with strangers whose identities you cann...

Matrimonial Privacy for Parents Managing a Profile on Behalf of Their Child

TL;DR: When a parent creates or manages a matrimonial profile for an adult child, privacy considerations shift — it's not just the child's data being shared, but often the parent's own contact details and family information too. Here's what to think through specifically. It's a common, culturally normal pattern in India for parents to create and actively manage a matrimonial profile on behalf of an adult son or daughter — sometimes with full involvement from the child, sometimes with the parent taking the lead more independently. This arrangement raises a distinct set of privacy considerations that a profile the individual manages themselves doesn't quite have. Whose contact details actually end up on the profile When a parent manages the profile, it's common for the parent's own phone number and email to be used as the primary contact — meaning inbound interest, messages, and eventually scam attempts land with the parent rather than (or in additio...

Matrimonial Site Verification Compared: What Shaadi.com, BharatMatrimony, and Jeevansathi Actually Check

TL;DR: India's major matrimonial platforms all claim some form of verification, but what's actually checked — and how thoroughly — varies. Here's what each platform states about its own process, so you know what you're relying on versus what you still need to verify yourself. Before comparing, one honest framing: platform-level verification is a helpful first filter, not a replacement for your own diligence. Even on platforms with stronger claimed verification, individual profile fraud still occurs — treat what follows as context for how much platform-side checking you're starting with, not a guarantee. Shaadi.com Shaadi.com is among the largest and longest-running matrimonial platforms in India, with a notably large NRI user base and a premium positioning that includes features like video calling and what it describes as enhanced privacy tools. It's generally positioned as offering broader reach and scale — a large, diverse pool of profiles — with securit...

What to Do If You’ve Been a Victim of Matrimonial Fraud

TL;DR: Acting quickly and in the right order — reporting, securing your finances, and leaning on support rather than isolating — meaningfully improves both recovery odds and how you come through this. Here's the specific path forward. If you're reading this because it's already happened, the most important thing to know first: this is a documented, common crime pattern, not a personal failure. Matrimonial fraud is built specifically to exploit trust and emotional investment — falling for it reflects the sophistication of the scam, not a lack of judgment on your part. Step 1: Stop all further contact and financial engagement immediately The moment you recognize fraud, cut off further communication and, critically, don't send any additional money — even if there's pressure framed as "one last payment to fix everything." This pressure to send more is itself a common continuation of the scam, exploiting the sunk-cost feeling of having already invested mo...