City
Epaper

Financial data of over 9 mn cardholders leaked, including from SBI: Researchers

By IANS | Updated: October 12, 2022 17:55 IST

New Delhi, Oct 12 Cyber-security researchers on Wednesday said they have discovered a massive leak involving over nine ...

Open in App

New Delhi, Oct 12 Cyber-security researchers on Wednesday said they have discovered a massive leak involving over nine million cardholders' financial data that includes customers of the State Bank of India (SBI).

The threat intelligence team of AI-driven Singapore-headquartered CloudSEK discovered a threat actor advertising a database of 1.2 million cards for free on a Russian-speaking Dark Web cybercrime forum.

This followed another incident of 7.9 million cardholder data advertised on the BidenCash website.

Unlike previous records, this time, the hackers released sensitive Personal Identifiable Information (PII) information such as SSN, card details and CVV, the team revealed.

"State Bank of India, Fiserv Solutions LLC, American Express were some of the top banking institutions which were affected. There were approximately 508,000 debit cards breached with 414,000 records of Visa payment network followed by Mastercard," the security researchers said.

The majority of personal emails associated with the card details were exposed. Other official emails records were found to be exposed associated with SoftBank, Bank of Singapore, and World Bank from the previous data breach by BidenCash.

"Marketplaces like BidenCash emerge frequently where the threat actors trade-sensitive card data for carding and cloning services. While the modern day security mechanisms are able to minimise the impact, threat actors regularly check deploy new methods to bypass them," said Rishika Desai, Cyber Threat Researcher- CloudSEK.

Leaked PII could enable threat actors to orchestrate social engineering schemes, phishing attacks, and even identity theft.

"Exposed card details might be used by them to carry out attacks such as card trafficking, card cloning, and unauthenticated transactions to facilitate illegal purchases," said researchers.

The motivation behind these data leaks was to gain more traffic to their website and establish a reputation.

BidenCash forum became active in early February 2022. Post that the threat actor resorted to various ways to gain traffic to his website such as spamming comments on websites.

"On a personal level, trying to track your card transactions, being aware of malicious sites luring off a great deal can help prevent to a greater extent. With the BidenCash group trying to gain popularity through various measures, leaking card data motivates other groups to follow the same steps," Desai noted.

Disclaimer: This post has been auto-published from an agency feed without any modifications to the text and has not been reviewed by an editor

Tags: Axis BankFiserv solutions llcRishika desaiNew DelhiState Bank Of IndiaBank branchesIndia servicesThe new delhi municipal councilIcici groupDelhi south-westNational payment corporation of indiaGoogle research indiaState for education
Open in App

Related Stories

CricketIND-W vs AUS-W, 3rd ODI: Australia Women Win Toss, Opt to Bat Against India in Series Decider; Check Playing XIs

CricketWhy Is India Women’s Cricket Team Wearing a Pink Jersey in IND-W vs AUS-W 3rd ODI 2025 Match?

CricketIND-W vs AUS-W 3rd ODI LIVE Cricket Streaming: When and Where to Watch India Women vs Australia Women Final Match

NationalBihar: Furniture Showroom Goods Worth Lakhs Gutted in Nalanda Blaze (Watch Video)

NationalVijayapura Bank Robbery: Masked Thieves Loot 12–13 Kg Gold and Rs 1 Crore Cash From SBI Branch in Karnataka

Technology Realted Stories

TechnologyED raids 6 Reliance Infrastructure-linked premises in Indore and Mumbai over FEMA probe

TechnologyIndian equity indices end slightly lower ahead of RBI's MPC outcome

TechnologyIndia's corporate credit profile demonstrates resilience amid global uncertainties: Report

TechnologyPhonePe, Mastercard’s new tap and pay feature to enable contactless payments in India

TechnologyAdani Electricity provides 653 temporary power connections to Navratri, Durga Puja Pandals