HomeNewsTechnologyEXCLUSIVE | 10 mobile apps using Razorpay payment gateway expose transaction keys

EXCLUSIVE | 10 mobile apps using Razorpay payment gateway expose transaction keys

CloudSEK said leaked API details can be exploited to gain personal details of users, like phone numbers and email addresses, and also to initiate unauthorised refunds. Mobile applications of companies like Isha Foundation, Zify and Ruptok named in the report.

September 16, 2021 / 17:52 IST
Story continues below Advertisement
API, or Application Programming Interface, is a software intermediary that allows two applications to talk to each other. It is the messenger that delivers your request to the service provider you're requesting it from and then delivers the response back to you. [Image: Shutterstock]
API, or Application Programming Interface, is a software intermediary that allows two applications to talk to each other. It is the messenger that delivers your request to the service provider you're requesting it from and then delivers the response back to you. [Image: Shutterstock]

Nearly 10 mobile applications using Razorpay as payment gateway are exposing secret keys, putting personal data of users at risk, a report by cybersecurity company CloudSEK said.

The report made it clear that Razorpay is not at fault and it’s the individual companies that are to be blamed.

Story continues below Advertisement

The 10 mobile applications include those of Jaggi Vasudev’s Isha Foundation, steel trading e-commerce app Steeloncall.com, vehicle hiring app Zify, fintech platform Ruptok and Spark Live. The API keys are exposed in these applications, the report said.

About 250 apps use the Razorpay API for financial transactions.