India's largest housing finance company quietly fixed a critical authentication flaw on its customer portal that allowed anyone on the internet to pull personally identifiable information of an estimated 500,000 borrowers without logging in, according to a coordinated disclosure verified by CERT-In and reviewed by VARIndia.
The vulnerability, in the LIC Housing Finance (LIC HFL) customer portal at customer.lichousing.com, exposed full name, date of birth, Permanent Account Number (PAN), mobile number, residential address, and email for any borrower whose internal customer ID could be guessed or sequentially enumerated. It was reported to the Indian Computer Emergency Response Team on April 29, 2026, and confirmed fixed on May 6, 2026, under reference number CERTIn-52457426.
The flaw was found and reported by Vibhum Sharad Dubey, an independent security researcher and an LIC HFL borrower. VAR India reviewed the full email correspondence with CERT-In, including PGP-signed acknowledgements from the agency's Incident Response Help Desk.
A textbook IDOR on an authenticated-looking endpoint
The vulnerability is a classic Insecure Direct Object Reference (IDOR), a category of broken access control listed in the OWASP Top 10. The portal exposed a backend endpoint that accepted a numeric customer ID parameter, called cifid in LIC HFL's implementation, and returned the full customer record. The endpoint sat under a path segment named "authorized," but performed no session validation or ownership check on the caller.
In his report to CERT-In, Dubey wrote that incrementing or substituting the cifid value returned data for unrelated customers. He used Burp Suite to intercept and replay the request. The Proof-of-Concept submitted to CERT-In showed the response payload included PAN numbers and dates of birth in clear text.
"An authorization flaw allows unauthenticated users to access customer records by manipulating a request parameter," Dubey said in his disclosure, which VAR India has reviewed. He estimated potential exposure at over 500,000 customer records based on the enumeration range, though he stopped probing after confirming the pattern and did not exfiltrate data.
CERT-In acknowledged the report on April 30, requested a video proof-of-concept the same day, and confirmed remediation on May 6 after coordinating with LIC HFL. Dubey independently re-tested the endpoint and confirmed the fix the same day.
Scale and downstream risk
LIC HFL is India's largest housing finance company by loan book, with a portfolio of roughly Rs 3.07 lakh crore as of March 31, 2025, and a network of more than 450 offices, according to the company's FY25 annual report. The customer portal is used by salaried, self-employed, and non-resident borrowers to track loan status, EMI schedules, and interest certificates.
The combination of PAN and date of birth is particularly sensitive in the Indian context. The two fields together are sufficient for KYC verification on several fintech platforms, can be used to query credit bureau records, and are commonly exploited for SIM-swap reconnaissance and PAN-based GST misuse. Mobile numbers and email addresses paired with verified PAN data also enable targeted phishing at scale.
In the disclosure correspondence, Dubey asked CERT-In to consider issuing a public advisory so affected customers could take precautions against identity fraud and PAN misuse. CERT-In has not, as of publication, issued such an advisory.
Part of a pattern in Indian BFSI
The LIC HFL flaw is the third high-profile IDOR disclosure affecting Indian financial or government systems in eight months. In September 2025, researchers Akshay C.S. and a co-discoverer reported a similar IDOR in the Income Tax Department's e-Filing portal that exposed PAN, Aadhaar, and bank details for an estimated 135 million registered users; CERT-In coordinated remediation. In October 2025, security firm TwinTech Solutions disclosed an unauthenticated IDOR in a Shriram Life Insurance web page that exposed PAN, bank account, and policy data.
Industry analysts have repeatedly flagged broken access control as the dominant API security failure in Indian BFSI deployments. The category remains the top entry in the OWASP Top 10 for web applications and the OWASP API Security Top 10.
Governance questions and company response
The disclosure window coincides with a leadership gap in LIC HFL's information security function. According to a regulatory filing on the BSE, the company informed exchanges on April 20, 2026, that Paritosh Chaturvedi had ceased to be the company's Chief Information Security Officer, citing an internal transfer posting. The disclosure to CERT-In was filed nine days later. LIC HFL has not, as of publication, named a successor in public filings.
LIC HFL had not issued a customer notification or filed a separate stock-exchange disclosure regarding the incident at the time of writing. The Companies (Management and Administration) Rules and CERT-In's April 2022 directions require regulated entities to report cybersecurity incidents to the agency within six hours; the rules do not currently mandate direct customer notification for vulnerability disclosures that are remediated before exploitation is confirmed.
LIC HFL did not immediately respond to a request for comment.
See What’s Next in Tech With the Fast Forward Newsletter
Tweets From @varindiamag
Nothing to see here - yet
When they Tweet, their Tweets will show up here.
