top of page

Risk of losing business accounts using only a phone number: Lessons from the Tata Nexarc incident

Armed only with a registered phone number, an attacker could easily gain control of accounts on Tata Nexarc - a B2B procurement platform connecting small and medium-sized enterprises (SMEs) with construction material and steel suppliers in India. This severe security flaw stemmed from a loophole in the OTP authentication process, paving the way for account takeover risks without requiring SMS interception or social engineering attacks.

Flaw in the OTP transmission process

Typically, an SMS-based One-Time Password (OTP) serves as proof that the user actually possesses the registered phone number. However, security researchers discovered that when Tata Nexarc's login interface called the CheckForUsersRegisteredWithEmailOrMobileNoAndSendOTP.do API endpoint, the system initiated the SMS delivery to the device while simultaneously returning the exact same OTP code within the response payload sent back to the browser.

otp-process
Security loophole in the OTP transmission process

Although the data stream transmitted via the API was encrypted with client-side JavaScript using AES, the browser inherently had to decrypt it for processing. Consequently, an attacker could simply set a breakpoint in the JavaScript code to view the data in plaintext. The decrypted response revealed the otpGeneratedForMobile field, which contained the exact OTP string sent via SMS. By extracting this code directly, the attacker could easily complete the login process for the target account - even though the front-end application interface had no operational need for this redundant data field.

Blast radius and admin exposure risks

According to research from Eaton-Works, the risk varied depending on the privileges of the exploited account. Testing revealed that a predictable phone number was linked to the primary Tata Business Hub account - which holds administrative privileges over the system. This unauthorized access allowed malicious actors to tamper with company management categories, employee administration, order history, subscription access, licenses, shipping details, commercial proposals, marketplace features, and notifications.

Researchers also obtained administrative privileges to an account associated with Tata Steel using a phone number tied to that organization. Although the vulnerability analysis did not detail a method for mass phone number scraping - limiting the immediate threat of widespread automated attacks - threat actors could still identify targets through OSINT (open-source intelligence) or leaked employee lists following an initial account compromise.

Remediation timeline and lessons in authentication security

The vulnerability was reported to the Indian Computer Emergency Response Team (CERT-In) on July 30, 2026. CERT-In acknowledged the report on the same day and verified that the issue was fully resolved on July 31, 2026, by completely removing the otpGeneratedForMobile field from the API response payload. Detailed public disclosure followed on August 24, 2026.

This incident underscores a foundational rule in OTP implementation: authentication codes must never be reflected back to the client, logged in plaintext, or exposed via browser-accessible APIs. Verification must occur strictly server-side, accompanied by response payload minimization, strict expiration TTLs, rate limiting, and continuous monitoring. Furthermore, integrating Threat Intelligence into a SOC (Security Operations Center) serves as a crucial defense layer to detect and block account takeover (ATO) threats early on.

Solutions from IPSIP Vietnam: Elevating cybersecurity and securing authentication flows

The Tata Nexarc incident demonstrates how critical vulnerabilities can stem from minor technical flaws in application business logic. To avoid falling into the same trap, enterprises require a proactive security strategy that spans from source code reviews to operational monitoring.

As a cybersecurity expert, IPSIP Vietnam delivers a comprehensive solution ecosystem to help businesses eliminate these risks. Through Vulnerability Assessment & Penetration Testing (Pentest) services, IPSIP’s engineering team proactively audits and identifies flaws in API communications or authentication logic errors (such as OTP leaks) before hackers can exploit them.

ipsip-viet-nam
IPSIP Vietnam provides comprehensive security solutions to optimize cybersecurity infrastructure

In addition, deploying IPSIP’s 24/7 Security Operations Center (SOC), integrated with Privileged Access Management (PAM) technologies, ensures continuous protection for enterprise IT infrastructures. Any abnormal behavior, privilege escalation attempts, or unauthorized tampering with administrative accounts are flagged early and mitigated immediately. This forms a robust shield that helps organizations safeguard digital assets and maintain customer trust.

Reference: ADSECVN

Comments


follow ipsip vietnam.png
40051abd5a76713af8f015988fc6780e-blue-phone-icon-with-a-wave-on-it.webp
Logo-Zalo-Arc.webp
pngtree-minimal-calendar-icon-vector-png-image_21233134.png
IPSIP logo transparent.png

IPSIP VIETNAM ONE MEMBER LIMITED LIABILITY COMPANY (IPSIP VIETNAM OMLLC)

Tax code: 0313859600

🏢 SH05.01, B4 Street, Saritown Area, An Khanh Ward, Ho Chi Minh City, Vietnam

​☎  +84 918 397 489

  • Linkedin
  • Facebook
  • TikTok
  • Email liên hệ
png-clipart-iso-iec-27001-information-security-management-iso-iec-27002-international-orga
soc 2 type ii

Our Services

Sign up to receive in-depth cybersecurity documents and news from IPSIP Vietnam.

bottom of page