• About
  • Privacy Policy
Open Security Labs
No Result
View All Result
No Result
View All Result
Open Security Labs
No Result
View All Result
Home Cybersecurity

India’s Top Financial Data Breaches: Investigating 4 Notorious Incidents in Banking

OpenBuckets Support by OpenBuckets Support
24th February 2024
in Cybersecurity, Data Breaches, Data security, News
0
top financial data breach in india
479
SHARES
1.5k
VIEWS
Share on FacebookShare on Twitter

In an age where data is a currency of its own, the security of financial information is paramount. However, India has witnessed several notorious data breaches within its banking sector, shaking customer trust and prompting serious concerns about data protection practices. Let’s explore four infamous data breaches in Indian banking history, examining their details and consequential aftermaths.

  1. State Bank of India (SBI) Data Breach
  2. Bank of Baroda (BoB) Data Leak
  3. 2019 Credit and Debit Card Data Breach
  4. Cyberattack on Union Bank of India

State Bank of India (SBI) Data Breach

In 2019, the State Bank of India (SBI) encountered a substantial data breach, exposing sensitive information from an alarming 422 million consumers. The breach stemmed from an unsecured server hosting data from SBI Quick, a text message and call-based service, leaving personal details vulnerable. Discovered by a security researcher and reported to TechCrunch, the breach revealed phone numbers, bank balances, and partial account numbers, raising concerns about potential fraud and identity theft.

SBI swiftly secured the database but faced scrutiny over its handling of the incident, highlighting the need for robust security measures and transparent communication. This breach underscores the critical importance of cybersecurity in safeguarding customer data and maintaining trust in financial institutions. Going forward, SBI must prioritize strengthening its security protocols and proactively rebuilding customer confidence in its commitment to protecting sensitive information.

Bank of Baroda (BoB) Data Leak

Despite initially refuting allegations, internal documents revealed malpractices, prompting the Reserve Bank of India (RBI) to ban BoB from onboarding new ‘bob World’ customers. The RBI cited supervisory concerns and mandated BoB to rectify deficiencies before resuming onboarding. BoB subsequently suspended over 50 employees involved in irregularities, emphasizing efforts to address concerns and restore customer trust under RBI supervision.

In 2021, Bank of Baroda (BoB), one of India’s largest public sector banks, found itself embroiled in a major data breach that exposed sensitive customer information. In September of that year, Bank of Baroda (BoB) launched the ‘bob World’ digital banking app, aiming to consolidate banking services under four pillars (save, invest, borrow, and shop). However, the initiative turned disastrous as bank staff resorted to unethical practices to inflate app downloads and sign-ups, including linking unrelated mobile numbers to customer accounts. This led to artificial success metrics and security risks for customers.

2019 Credit and Debit Card Data Breach

In October 2019, a staggering 1.3 million credit and debit card records found their way onto the dark web’s notorious marketplace, Joker’s Stash, raising alarms globally. Shockingly, over 98% of these compromised cards belonged to various Indian banks, fetching prices upwards of $100 per card. Group-IB, headquartered in Singapore, disclosed the breach, unveiling sensitive data, including card numbers, expiry dates, CVVs, and complete personal details like names, emails, and addresses.

Suspicions point to skimming devices installed on ATMs or Point of Sale (PoS) systems or the sophisticated Magecart attacks targeting e-commerce websites. The gravity of the breach escalated in February 2020 when an additional 460,000 cards surfaced on Joker’s Stash, each carrying personal identifiers and selling for $9. This breach stands as one of the largest in history, prompting ongoing investigations to uncover the full extent of the cybercrime.

Cyberattack on Union Bank of India

In July 2017, a notable cyberattack impacted one of India’s largest financial institutions, Union Bank of India. The incident began with an employee innocuously opening an email attachment, unaware that it contained a malicious code. This oversight granted hackers unauthorized entry into the bank’s systems, allowing them to extract sensitive data. Compounding the issue was a forged central bank email accompanying the attachment, which misled the employee into inadvertently aiding the breach.

The repercussions were severe: the hackers acquired Union Bank’s access codes for the Society for Worldwide Interbank Financial Telecommunication (SWIFT), a crucial system for international transactions. Utilizing these stolen codes, the perpetrators executed a sophisticated heist, transferring a substantial $170 million to a Union Bank account at Citigroup Inc. in New York.

Stay tuned for more updates on cybersecurity and financial data protection. Read more on Data Breaches

Share this:

  • Share on X (Opens in new window) X
  • Share on Facebook (Opens in new window) Facebook
  • Share on LinkedIn (Opens in new window) LinkedIn
  • Share on Telegram (Opens in new window) Telegram
  • Share on WhatsApp (Opens in new window) WhatsApp
  • Share on Mastodon (Opens in new window) Mastodon
  • Email a link to a friend (Opens in new window) Email

Related


Discover more from Open Security Labs

Subscribe to get the latest posts sent to your email.

Tags: cybersecuritydarkwebdata leakleaksmisconfigured bucketsOpenBuckets
Previous Post

A Week of Daunting Challenges for Australia – 3 Cybersecurity incidents shook the industry

Next Post

Supply Chain Attacks: The Biggest Cybersecurity Nightmare – 3 Intriguing Case Studies

Related Posts

SquidLoader
Uncategorized

SquidLoader: A New Evasive Malware Targeting Chinese Organizations (0penBuckets)

23rd June 2024
Securing Cloud Identities: Defending Against Networkless Attacks in the SaaS Era 101
Uncategorized

Securing Cloud Identities: Defending Against Networkless Attacks in the SaaS Era 101

3rd May 2024
Unraveling the Akira Ransomware Menace: How a Ruthless Cybercriminal Gang Raked in $42 Million
Uncategorized

Unraveling the Akira Ransomware Menace: How a Ruthless Cybercriminal Gang Raked in $42 Million

26th April 2024
Safeguarding Your Apple Products: 9 Steps to Mitigate the Risk of Arbitrary Code Execution
Uncategorized

Safeguarding Your Apple Products: 9 Steps to Mitigate the Risk of Arbitrary Code Execution

19th April 2024
Safeguarding Multi-Factor Authentication: Cisco Duo Addresses Data Breach
Uncategorized

Safeguarding Multi-Factor Authentication: Cisco Duo Addresses Data Breach

17th April 2024
APT36’s Cyber Arsenal: ElizaRAT and Innovative Linux Attack Vectors
Cybersecurity

APT36’s Cyber Arsenal: ElizaRAT and Innovative Linux Attack Vectors

14th April 2024
Next Post
supply chain attack

Supply Chain Attacks: The Biggest Cybersecurity Nightmare - 3 Intriguing Case Studies

  • About
  • Privacy Policy

© 2024 OpenSecurityLabs.com

No Result
View All Result
  • About
  • Privacy Policy

© 2024 OpenSecurityLabs.com

Discover more from Open Security Labs

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from Open Security Labs

Subscribe now to keep reading and get access to the full archive.

Continue reading