Records of millions credit cards left unprotected by payments startup
By MYBRANDBOOK
According to news, New York-based payments startup left millions of credit card transaction records exposed for anyone to see on the internet for nearly three weeks before securing it. Security researcher Anurag Sen found the database belonging to card payments processor Paay, a news portal reported after alerting the company about the finding.
The database was pulled offline by Paay after it became aware of the issue. Paay co-founder Yitz Mendlowitz said that on April 3, they spun up a new instance on a service they are currently in the process of deprecating. An error was made that left that database exposed without a password.
To prevent fraudulent transactions, Paay verifies payments on behalf of selling merchants, but anyone could access the data inside because there was no password on the server. A review of a portion of the data base by the news portal revealed that each transaction contained credit card number and expiry date besides the amount spent, but as the data did not include names of the cardholder as well as card verification values, the exposure did not make it any easier for fraudsters to misuse it. Mendlowitz, however, said that his company does not store card numbers.
During this time, this kind of exposed credit card transaction records could have lead to a bigger crisis. If you remember, Google recently reported that in just one week from 6 to 13 April, it saw more than 18 million daily malware and phishing emails related to Covid-19 scams.
Also, Hackers are creating scam sites similar to COVID-19 relief packages. These scam websites use the news of the coronavirus financial incentives, and fears about coronavirus to try and trick people into using the websites or clicking on links. Check Point Researchers found that since January, a total of 4,305 domains relating to new stimulus/relief packages have been registered globally. In March 2020, a total of 2,081 new domains were registered -38 malicious and 583 suspicious. In the first week of April, 473 were registered – 18 malicious, 73 suspicious.
Legal Battle Over IT Act Intensifies Amid Musk’s India Plans
The outcome of the legal dispute between X Corp and the Indian government c...
Wipro inks 10-year deal with Phoenix Group's ReAssure UK worth
The agreement, executed through Wipro and its 100% subsidiary,...
Centre announces that DPDP Rules nearing Finalisation by April
The government seeks to refine the rules for robust data protection, ensuri...
Home Ministry cracks down on PoS agents in digital arrest scam
Digital arrest scams are a growing cybercrime where victims are coerced or ...
Icons Of India : NANDAN NILEKANI
Nandan Nilekani is the Co-Founder and Chairman of Infosys Technologies...
Icons Of India : Anil Agarwal
Anil Agarwal, the Founder and Chairman of Vedanta Resources Ltd., is r...
ICONS OF INDIA : VINAY SINHA
Vinay Sinha is the Managing Director of Sales for the India Mega Regio...
ITI - ITI Limited
ITI Limited is a leading provider of telecommunications equipment, sol...
HPCL - Hindustan Petroleum Corporation Ltd.
HPCL is an integrated oil and gas company involved in refining, market...
ECIL - Electronics Corporation of India Limited
ECIL is distinguished by its diverse technological capabilities and it...
Indian Tech Talent Excelling The Tech World - RAVI KUMAR S, CEO- Cognizant
Ravi Kumar S, appointed as CEO of Cognizant in January 2023, sets the ...
Indian Tech Talent Excelling The Tech World - Satya Nadella, Chairman & CEO- Microsoft
Satya Nadella, the Chairman and CEO of Microsoft, recently emphasized ...
Indian Tech Talent Excelling The Tech World - Rajiv Ramaswami, President & CEO, Nutanix Technologies
Rajiv Ramaswami, President and CEO of Nutanix, brings over 30 years of...