According to a report by UK-based data security firm BugsBounty.Com, 72 out of the 100 major startups it analysed were "negligent" in implementing and maintaining reasonable security practices and procedures.
Read more from our special coverage on "CYBERCRIME"
While the report did not name the companies, it said these were across segments like eCommerce (30), classifieds (14), finance and fin-tech (7), healthcare (7), food-tech (5) and hyperlocal services (3).
With growing Internet penetration and data packs becoming more affordable, consumer-focussed startups have seen business booming. Be it ordering food or furniture online or paying bills, consumers today are much more comfortable making purchases on the web and sharing details like email IDs, address and phone numbers.
"We have been speaking to some of these firms. We have warned them that they may be liable to pay massive compensation to users whose 'personal' and 'sensitive' data they store including passwords and financial information," BugsBounty.Com Director Ankush Johar told PTI.
Citing Section 43A (Compensation for failure to protect data) of Indian IT Act, Johri said the companies may have to shell out as much as Rs 5 crore in case of a data breach.
He added that this is critical, especially since billions of dollars of investor money is riding on these ventures.
"Also, 22 out of the 100 were found to have web server software vulnerabilities that pertain to software on their servers that is known to have bugs, but these startups have not patched those," he said.
This puts all the data on their server at risk including their software code, databases in entirety among others, he added.
Explaining the attack, Johar said a user receives an email asking them to login to the company's and they comply.
"The link is the same URL as that of the startup. The 'cautious' user ensures that the URL in the browser is the same as the sender. The user inputs his or her username and password because it appears to be completely genuine," he said.
However, instead of the company, it is the hacker who receives the username and password.
"This is not a phishing attack because the consumer is indeed logging into the company's website. However, because of the vulnerabilities that the website has, the consumer data can get into the hands of the hacker," he said.
Also, the magnitude of the threat is even higher because with mobile penetration soaring, Johar said.
Consumers on their part should ensure that they change their passwords regularly and keep different sets of passwords for critical services like banking and email, and another set for other non-critical services.
"They shouldn't share any extra information that is not critical for the companies," he said.
You’ve reached your limit of {{free_limit}} free articles this month.
Subscribe now for unlimited access.
Already subscribed? Log in
Subscribe to read the full story →
Smart Quarterly
₹900
3 Months
₹300/Month
Smart Essential
₹2,700
1 Year
₹225/Month
Super Saver
₹3,900
2 Years
₹162/Month
Renews automatically, cancel anytime
Here’s what’s included in our digital subscription plans
Exclusive premium stories online
Over 30 premium stories daily, handpicked by our editors


Complimentary Access to The New York Times
News, Games, Cooking, Audio, Wirecutter & The Athletic
Business Standard Epaper
Digital replica of our daily newspaper — with options to read, save, and share


Curated Newsletters
Insights on markets, finance, politics, tech, and more delivered to your inbox
Market Analysis & Investment Insights
In-depth market analysis & insights with access to The Smart Investor


Archives
Repository of articles and publications dating back to 1997
Ad-free Reading
Uninterrupted reading experience with no advertisements


Seamless Access Across All Devices
Access Business Standard across devices — mobile, tablet, or PC, via web or app
)