Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Darkhub Hacking-for-Hire Portal: Crypto Advertises Fraud
May 7, 2026
CloudZ RAT Steals SMS OTPs via Microsoft Phone Abuses Link
May 6, 2026
QLNX Credential Theft Targets Developers for Supply Chain Comprom
May 6, 2026
Home/CyberSecurity News/HSBC India Mandates All-Uppercase Passwords for Asks Customers
CyberSecurity News

HSBC India Mandates All-Uppercase Passwords for Asks Customers

HSBC India announced a significant policy change for its internet banking customers: as of April 6, 2026, all passwords must be entered using uppercase letters exclusively. The mandate, communicated...

Sarah simpson
Sarah simpson
April 1, 2026 2 Min Read
3 0

HSBC India announced a significant policy change for its internet banking customers: as of April 6, 2026, all passwords must be entered using uppercase letters exclusively.

The mandate, communicated via official customer emails, has sparked widespread concern among technical experts regarding the bank’s credential storage practices and overall security posture.

The Uppercase Migration

According to the bank’s recent communications, customers must type their existing passwords in capital letters going forward. For example, a user with the password “Test123” must now enter “TEST123” to access their account.

HSBC Bank Notification

By upgrading to a true case-sensitive login portal, the bank’s backend now requires the exact uppercase input to match the existing uppercase hashes stored in its database.

Despite the bank’s explanation regarding legacy hashing, security researchers have labeled the directive a massive red flag. Standard cybersecurity practices dictate that credentials must always be stored as one-way hashes, rendering the original input unreadable.

As noted by security researchers, it should be literally impossible for a vendor to know your credentials’ casing unless they weren’t storing passwords as hashes. This anomaly has fueled industry speculation about potential plaintext password storage or deeply flawed legacy security practices.

Adding to the confusion, the bank’s official FAQ still states that passwords are not case-sensitive, creating a glaring contradiction in their public documentation.

Critics have been quick to point out that this uppercase mandate actively weakens user security. By eliminating lowercase letters from the allowable character set, the bank effectively cuts password options in half.

A password that mixes cases has higher entropy and is inherently harder to crack. Restricting users to an uppercase-only format drastically reduces the number of possible character combinations, which makes accounts significantly more vulnerable to automated brute-force attacks and credential stuffing.

Security experts recommend that users proactively reset all passwords to establish new, strong credentials for better protection.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCybersecuritySecurity

Share Article

Sarah simpson

Sarah simpson

Sarah is a cybersecurity journalist specializing in threat intelligence and malware analysis. With over 8 years of experience covering APT groups, zero-day exploits, and advanced persistent threats, Sarah brings deep technical expertise to breaking cybersecurity news. Previously, she worked as a security researcher at leading threat intelligence firms, where she analyzed malware samples and tracked cybercriminal operations. Sarah holds a Master's degree in Computer Science with a focus on cybersecurity and is a regular contributor to major security conferences.

Previous Post

Critical Chrome Zero-Day Actively Exploited – Patch

Next Post

Vertex AI Vulnerability Exposes Google Cloud Sensitive

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Argo CD ServerSideDiff Flaw Allows Kubernetes Secret Theft
May 6, 2026
Prolific Russian Ransomware Member Sentenced to Group Months
May 6, 2026
Detect Phishing-to-RMM Attacks Analysts Trusted-Tool
May 6, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Sarah simpson
Sarah simpson
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Detects Critical MongoDB CVE-

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us