preview

India 's Largest Data Security Breach

Decent Essays

3.2 million debit cards issued by some of India’s largest banks were exposed to a malware induced security breakdown around Mid-2016 making it one of India’s largest data security breach. Malware that could damage ATM system was injected into the ATM payment service machine, which permitted unauthorized persons to access credentials of users. The NPCI (National Payments Council of India), an umbrella organization facilitating retail payments warned banks that unauthorized transactions were being generated from China and USA. SISA, a security auditing firm reported that a sophisticated injection of malware (a piece of malicious software code) in the Hitachi Payments Services Systems led to the compromise of the details of these debit cards. …show more content…

Later in September, banks again reported transactions to the company after which an external audit agency, SISA Information Security was called to conduct a forensic audit on the case. (Source: Deccan Herald, Oct 20, 2016)
SISA completed its final assessment report on the breach of security protocols, which led to the potential compromise of debit cards between May 21 and July 11, 2016. SISA’s report pointed out a sophisticated malware injected (a piece of malicious software code) in the Hitachi Payments Services systems, which could compromise the details of these debit cards. The code was written in such a manner that it concealed its traces during the compromise period. “While behavior of the malware and the penetration into the network has been deciphered, the amount of data exfiltrated during the above compromise period is unascertainable due to secure deletion by the malware” said Loney Anthony. (Source: Press Release by Hitachi Payment Services).
The Reserve Bank of India has been asking banks to enhance their digital security and the Hitachi statement comes a day after the central bank announced formation of an inter-disciplinary standing committee on cyber-security to review threats, study security standards and suggest appropriate policy interventions. (Source: Press Trust of India, 09 Feb 2017)

Method

Working of ATM network
ATM systems of most of the banks in the country are delegated to third parties who supply the ATM machine and the

Get Access