financetom
Business
financetom
/
Business
/
Cybersecurity groups ask CERT-IN to investigate reported Mobikwik data breach
News World Market Environment Technology Personal Finance Politics Retail Business Economy Cryptocurrency Forex Stocks Market Commodities
Cybersecurity groups ask CERT-IN to investigate reported Mobikwik data breach
Mar 31, 2021 9:46 AM

Some industry groups that propagate internet freedom and cybersecurity have written to the Indian Computer Emergency Response Team (CERT-IN), the nodal agency in the country to deal with cybersecurity threats, to enquire into the reported data breach of users of payments platform Mobikwik.

Several cybersecurity researchers have reported over recent days of an alleged data breach of as many as 100 million Mobikwik users, though the company has denied the claim.

The Internet Freedom Foundation (IFF) on Wednesday said it has written to CERT-IN asking them to initiate an inquiry over the alleged data breach of Mobikwik users, and to ask executives of MobiKwik to provide detailed explanations to their office as per the Information Technology Act, 2000. The Free Software Movement of India has also asked CERT-In to carry out an investigation into the incident.

"India is witnessing one of the most significant data breaches in history. Users, security researchers and news organisations have reported that data of 10 crore Indians, including their passport details, addresses and phone numbers, is available for sale on the dark web. As per press reports, the data was in the custody of MobiKwik, which provides a mobile-based payment system. While MobiKwik has denied the data breach, independent security researchers and Indian Express have verified that details of MobiKwik users are available on the dark web. We have written to the Computer Emergency Response Team (CERT-IN) asking them to initiate an inquiry over the data breach in terms of Section 70B(6) of the Information Technology Act, 2000," IFF said in a social media post.

" In the letter, we have highlighted the concerns we have raised above and requested CERT-IN to conduct an inquiry into the data breach and conduct of MobiKwik, and require executives of MobiKwik to provide detailed explanations to their office in terms of Section 70B(6) of the Information Technology Act, 2000. We are hopeful that an enquiry by CERT-IN may compel MobiKwik to act responsibly and even provide compensation to its users as per Section 43A of the Information Technology Act, 2000," the post said.

Cybersecurity researcher Rajashekhar Rajaharia, who earlier this year also highlighted the Juspay data breach, had flagged the alleged data leak of Mobikwik users on February 26.

Rajaharia has said that the hackers have put up 8.2 TB of sensitive data of Mobikwik users on sale on the dark web, with an asking price of 1.5 Bitcoins. Bitcoin price in India as of Tuesday was Rs 42 lakh based on the quotes on Indian crypto exchanges. The data allegedly includes KYC data including Aadhar data of 36 million users, card data of 40 million users, and mobile and email data of 100 million users.

In a social media post on Tuesday, the company said that it had investigated the matter but did not find a breach.

"Some users have reported that their data is visible on the dark web. While we are investigating this, it is entirely possible that any user could have uploaded her/ his information on multiple platforms. Hence, it is incorrect to suggest that the data available on the dark web has been accessed from MobiKwik or any identified source," the company statement read.

Mobikwik also said in its post that it will conduct a forensic data security audit.

"When this matter was first reported last month, the company undertook a thorough investigation with the help of external security experts and did not find any evidence of a breach. The company is closely working with requisite authorities and is confident that security protocols to store sensitive data are robust and have not been breached. Considering the seriousness of the allegations, and by way of abundant caution, it will get a third party to conduct a forensic data security audit."

(Edited by : Abhishek Jha)

First Published:Mar 31, 2021 6:46 PM IST

Comments
Welcome to financetom comments! Please keep conversations courteous and on-topic. To fosterproductive and respectful conversations, you may see comments from our Community Managers.
Sign up to post
Sort by
Show More Comments
Related Articles >
Advance Auto Parts to Sell Worldpac to Carlyle for $1.5 Billion in Cash
Advance Auto Parts to Sell Worldpac to Carlyle for $1.5 Billion in Cash
Aug 23, 2024
06:39 AM EDT, 08/22/2024 (MT Newswires) -- Advance Auto Parts ( AAP ) said Thursday it has agreed to sell Worldpac Inc., its automotive parts wholesale distribution business, to funds managed by Carlyle Group ( CG ) for $1.5 billion in cash. The company expects net proceeds of about $1.2 billion after taxes and transaction fees. The deal, slated to...
BRIEF-Proreit Announces Agreement To Acquire Industrial Building In Montréal For $32.6 Million
BRIEF-Proreit Announces Agreement To Acquire Industrial Building In Montréal For $32.6 Million
Aug 23, 2024
Aug 21 (Reuters) - PRO Real Estate Investment Trust : * PROREIT ANNOUNCES AGREEMENT TO ACQUIRE INDUSTRIAL BUILDING IN MONTRÉAL FOR $32.6 MILLION * PRO REAL ESTATE INVESTMENT TRUST: PURCHASE PRICE TO BE FINANCED THROUGH NEW $21.2 MILLION FIVE-YEAR FIRST MORTGAGE AT RATE OF 5.10% Source text for Eikon: Further company coverage: ...
EHang Q2 Revenue Skyrockets 920% with Record eVTOL Deliveries: Details
EHang Q2 Revenue Skyrockets 920% with Record eVTOL Deliveries: Details
Aug 23, 2024
EHang Holdings Limited ( EH ) shares are trading higher after it reported second-quarter results. Revenue escalated 919.6% Y/Y to RMB102.0 million. In USD terms, revenue of $14.04 million beat the consensus of $12.58 million. Revenue benefitted from strong demand for the advanced EH216-S pilotless eVTOL vehicles. Gross profit surged 957.3% Y/Y to RMB63.7 million ($8.7 million), with a gross margin of 62.4%, up 2.2 percentage points Y/Y. Adjusted...
Biogen, Eisai's Mild Dementia Treatment Gets Marketing Authorization From UK Regulatory Authority
Biogen, Eisai's Mild Dementia Treatment Gets Marketing Authorization From UK Regulatory Authority
Aug 23, 2024
06:31 AM EDT, 08/22/2024 (MT Newswires) -- Biogen (BIIB) and Japan's Eisai Co. ( ESALF ) said early Thursday that their humanized amyloid-beta monoclonal antibody, lecanemab, received marketing authorization from the UK's regulatory authority. The company said lecanemab is indicated for the treatment of mild cognitive impairment and mild dementia due to Alzheimer's disease in certain types of adult patients....
Copyright 2023-2025 - www.financetom.com All Rights Reserved