financetom
Business
financetom
/
Business
/
Juspay data breach could get worse, cyber experts call company 'highly irresponsible'
News World Market Environment Technology Personal Finance Politics Retail Business Economy Cryptocurrency Forex Stocks Market Commodities
Juspay data breach could get worse, cyber experts call company 'highly irresponsible'
Jan 5, 2021 12:31 PM

The massive data breach on payments processing platform Juspay could have potentially grave consequences, even though the company has said that only non-sensitive data was breached and that customers were not at risk.

Juspay has confirmed that 3.5 crore records with masked card data and card fingerprint were breached, while email IDs and phone numbers were also compromised in a breach through unauthorised access in August 2020. Juspay processes over 4 million transactions worth Rs 1000 crore every day across e-commerce platforms such as Amazon, Swiggy, Ola and others.

Some of these companies said they are currently investigating, while Amazon has said they have 'not seen any impact from recent events as reported.”

Swiggy said 'no usable banking information such as the 16 digit card number of our customers was compromised in this incident'.

In a statement on the incident, Juspay said, "Juspay was victim of a cyberattack in one of isolated storage system on August 18, 2020. Our security audit conducted immediately after this incident has isolated the cause to an unrecycled access being compromised. The breach was restricted to an isolated system containing non-sensitive masked card primarily used for display purposes on merchant UI and cannot be used for completing a transaction. All of the customers’ full card numbers, order information, card PINs, or passwords are secure. The compromised data does not contain any transaction or order information.”

Juspay said that it did not inform customers at the time of the breach, because they were not at risk as masked card data, which only shows a few digits of the credit card number, cannot be used for completing a transaction.

What is concerning is that Juspay's public acknowledgement came after the matter was first brought to light on Monday by Rajshekhar Rajaharia, who says he is an independent cyber-security researcher and founder of a digital marketing firm.

While this breach occurred in August, Rajaharia came across this data on the dark web a few days ago in exchange for Bitcoin. And while the company says the number of affected users is 3.5 crore, Rajaharia says that based on information from the dark web seller there were 10 crore emails ID and phone numbers and 4.5 crore card details.

“On 3 January, I came across a seller on the dark web selling two files of data, one with email addresses and mobile numbers of 100 million customers, while the other had stored card data of 46 million transaction details."

Rajaharia has also dismissed the company's claims that since only non-sensitive data was compromised, there is no risk to customers. Rajaharia says the potential risk of such a breach is high, especially because card fingerprint data has been breached, and if a hacker can get access to the encrypted algorithm, it would lead to all the card data being exposed.

“The company masks the middle six-digit but also stores the fingerprint of the card number, which is a hash value of the card number. If the hacker can figure out the algorithm for the card fingerprint, they can easily unmask all digits,” Rajaharia said.

Tobby Simon, founder and president of Synergia Foundation hit out at Juspay for not disclosing the breach to customers immediately, and called the company ‘highly irresponsible.”

“Cryptography is based on algorithms. Quantum computing in AI can crack any cryptography,” Simon said.

“It is highly irresponsible of the company to say that consumers are not at risk. Some of the biggest online frauds have happened around e-commerce companies,” he said.

(Edited by : Abhishek Jha)

Comments
Welcome to financetom comments! Please keep conversations courteous and on-topic. To fosterproductive and respectful conversations, you may see comments from our Community Managers.
Sign up to post
Sort by
Show More Comments
Related Articles >
Tata Power Renewable Energy wins 200-MW project in collaboration with SJVN
Tata Power Renewable Energy wins 200-MW project in collaboration with SJVN
Nov 28, 2023
The firm and dispatchable renewable energy (FDRE) project, designed with a hybrid of solar, wind, and battery storage, is aimed at providing a stable and dispatchable energy supply during peak hours. Shares of Tata Power Company Ltd ended at ₹270.75, up by ₹12.60, or 4.88%, on the BSE.
Suzlon's S144–3 MW wind turbines get big boost from Indian government
Suzlon's S144–3 MW wind turbines get big boost from Indian government
Nov 15, 2023
Th Suzlon wind turbines received the RLMM (Revised List of Models & Manufacturers) listing from the Ministry of New and Renewable Energy, marking an important milestone for the successful commercialisation of the product. Shares of Suzlon Energy Ltd ended at ₹40.49, up by ₹1.85, or 4.79%, on the BSE.
This sustainable jewellery brand is luring some women away from gold
This sustainable jewellery brand is luring some women away from gold
Oct 30, 2023
Aulerth's offerings range from ₹5,000 to as high as ₹2.8 lakh. Are women willing to spend this much on jewellery made from scrap? Founder and CEO Vivek Ramabhadran definitely believes so. Aulerth produces couture-inspired pieces in association with designers like JJ Valaya, Suneet Varma, among others. It has reported 33% repeat customers in the past year and expects a spike to 40% soon.
SJVN secures 200-MW wind power project at ₹3.24 per unit
SJVN secures 200-MW wind power project at ₹3.24 per unit
Nov 16, 2023
Projected to generate 482 million units in its inaugural year post-commissioning, the cumulative energy generation over a 25-year span is anticipated to reach 12,050 million units. Shares of SJVN Ltd ended at ₹75.17, down by ₹0.50, or 0.66%, on the BSE.
Copyright 2023-2026 - www.financetom.com All Rights Reserved