financetom
Technology
financetom
/
Technology
/
Massive users’ data leak at MobiKwik, company denies breach
News World Market Environment Technology Personal Finance Politics Retail Business Economy Cryptocurrency Forex Stocks Market Commodities
Massive users’ data leak at MobiKwik, company denies breach
Mar 30, 2021 1:45 AM

Independent cybersecurity researchers have claimed that a database containing sensitive details of 35 lakh users of fintech start-up MobiKwik was up for sale online on a hacker forum on March 29. However, the digital wallet and payments company denied the breach.

A Moneycontrol report quoted a company spokesperson as saying: “Some media-crazed so-called security researchers have repeatedly attempted to present concocted files wasting precious time of our organization as well as members of the media. We thoroughly investigated and did not find any security lapses. Our user and company data is completely safe and secure.”

The Moneycontrol adds that the data leak includes 36,099,759 files spread over 8.2 TB. It has KYC details, addresses, email IDs, bank account numbers, credit card details, phone numbers and Aadhaar card numbers of MobiKwik customers.

Rajshekhar Rajaharia, a security researcher, had first reported about the leak in February this year. He has tweeted then: “Again!! 11 Crore Indian Cardholder's Cards Data Including personal details & KYC soft copy(PAN, Aadhar etc) allegedly leaked from a company's Server in India. 6 TB KYC Data and 350GB compressed mysql dump. (sic)”

Again!! 11 Crore Indian Cardholder's Cards Data Including personal details & KYC soft copy(PAN, Aadhar etc) allegedly leaked from a company's Server in India. 6 TB KYC Data and 350GB compressed mysql dump.@RBI @IndianCERT #InfoSec #dataprotection #Finance pic.twitter.com/yjc7davH3k

— Rajshekhar Rajaharia (@rajaharia) February 26, 2021A day later, in another tweet, he named MobiKwik and said that the company had removed an old post about a previous data breach from 2010. His tweet read: “As a customer of @MobiKwik It is my right to ask you, why you deleted you blog post of previous unauthorized server access(in 2010) after my tweet. (sic)”

As a customer of @MobiKwik It is my right to ask you, why you deleted you blog post of previous unauthorized server access(in 2010) after my tweet. I think it's a big controversy now.. what was the need of this step. Hiding things is not a solution. @IndianCERT @RBI #InfoSce pic.twitter.com/gmFhkA3j0D

— Rajshekhar Rajaharia (@rajaharia) February 27, 2021

In another tweet, French hacker Robert Baptiste, who goes by the pseudonym Elliot Alderson, posted a screenshot of the leaked data on Monday (March 29) and said: “Probably the largest KYC data leak in history. Congrats Mobikwik... (sic)”

Probably the largest KYC data leak in history. Congrats Mobikwik... pic.twitter.com/qQFgIKloA8

— Elliot Alderson (@fs0c131y) March 29, 2021

On Monday (March 29), many users confirmed seeing their details on a link from the dark web that began circulating online.

According to Technadu, the entire database can be bought for a price of 1.5 Bitcoin (around $85,000), which includes having the dark web portal taken offline and keeping everything exclusive.

A Business Standard report quoted an independent security researcher, Indrajeet Bhuyan, as saying that there is very little users can do, considering the large amount of data that has been leaked. “There is a big chance that scammers will be able to scam people and sound more authentic,” Bhuyan told Business Standard.

Comments
Welcome to financetom comments! Please keep conversations courteous and on-topic. To fosterproductive and respectful conversations, you may see comments from our Community Managers.
Sign up to post
Sort by
Show More Comments
Related Articles >
AIOZ Network Partners With Alibaba Cloud to Boost AI, Storage and Streaming Services
AIOZ Network Partners With Alibaba Cloud to Boost AI, Storage and Streaming Services
Mar 22, 2024
The two companies will establish a DePIN alliance in south-east Asia.AIOZ's native token is currently trading flat after the announcement, it is up by more than 200% in 30 days.AIOZ Network will use Alibaba Cloud to improve Web 3, AI, storage and streaming services.Decentralized infrastructure network (DePIN) AIOZ Network has become the leading blockchain partner in Alibaba Cloud’s Innovation Accelerator...
Japan braces for life with interest rates after historic change
Japan braces for life with interest rates after historic change
Mar 21, 2024
TOKYO (Reuters) - In the coming years, Satoaki Kanoh needs to replace almost a dozen ageing machines at his Tokyo-based maker of acrylic panels, a major undertaking that he worries will become even more expensive. Ideally, I'd like to do one a year. But I don't have that much money, Kanoh said of the customised pieces of machinery that cost...
Analysis-Apple antitrust suit mirrors strategy that beat Microsoft, but tech industry has changed
Analysis-Apple antitrust suit mirrors strategy that beat Microsoft, but tech industry has changed
Mar 22, 2024
(Reuters) - The U.S. government's antitrust lawsuit against Apple ( AAPL ) draws on the watershed 1998 case that broke Microsoft's ( MSFT ) stranglehold on desktop software, but that may prove to be an imperfect blueprint for addressing smartphone competition. The market for the iPhone today looks very different from the near-monopoly enjoyed by Microsoft's ( MSFT ) Windows...
Japan braces for life with interest rates after historic change
Japan braces for life with interest rates after historic change
Mar 21, 2024
TOKYO, March 22 (Reuters) - In the coming years, Satoaki Kanoh needs to replace almost a dozen ageing machines at his Tokyo-based maker of acrylic panels, a major undertaking that he worries will become even more expensive. Ideally, I'd like to do one a year. But I don't have that much money, Kanoh said of the customised pieces of machinery...
Copyright 2023-2026 - www.financetom.com All Rights Reserved