Beginning
April 6, 2026, HSBC India will require its internet banking customers to enter their passwords in uppercase letters only.
For example, a user with the password “Test123” must now enter “TEST123” to access their account.
The mandate, communicated via official customer emails, has
sparked widespread concern among technical experts regarding the bank’s credential storage practices and overall security posture.
As noted by security researchers, it should be literally impossible for a vendor to know your credentials’ casing unless they weren’t storing passwords as hashes. This anomaly has fueled industry
speculation about potential plaintext password storage or deeply flawed legacy security practices.
Critics have been quick to point out that this uppercase mandate actively weakens user security.
By eliminating lowercase letters from the allowable character set, the bank effectively cuts password options in half.
Beginning April 6, 2026, HSBC India will require its internet banking customers to enter their passwords in uppercase letters only.
cybersecuritynews.com