PNB Server exposed personal information of over 180 million customers
By MYBRANDBOOK
According to cyber security firm CyberX9, a vulnerability in the server of Punjab National Bank (PNB) allegedly exposed the personal and financial information of its about 180 million customers for about seven months. The vulnerability provided access to the entire digital banking system of PNB with administrative control. Meanwhile, the bank has confirmed the glitch but denied any exposure of critical data.
The bank has confirmed about the glitch but denied any exposure of critical data due to the vulnerability. PNB said "customer data/applications are not affected due to this" and "server has been shut down as a precautionary measure."
CyberX9 founder and MD Himanshu Pathak said that that vulnerability was found in an exchange server which is interconnected with other exchanges and shares all access -- including access to all email addresses which results in access to all email addresses.
"The vulnerability which we discovered was leading to the highest level of admin privilege in PNB's exchange servers. If you gain access to Domain Controller through an exchange server then the doors very easily open to make any computer accessible in the network. These computers even include those that are being used in their branches and other departments," Pathak said.
Responding to the cyber security firm’s comment, PNB said, "The server wherein the vulnerability was reported, was being used as one of the multiple Exchange Hybrid servers used to route emails from On-prem to Office 365 Cloud. There is no sensitive/critical data in this server."
InterGlobe’s Rahul Bhatia and C.P. Gurnani together announce
In a move that is set to transform the AI landscape, Rahul Bhatia, Group M...
Download masked Aadhaar to improve privacy
Download a masked Aadhaar from UIDAI to improve privacy. Select masking w...
Sterlite Technologies' Rs 145 crore claim against BSNL rejecte
An arbitrator has rejected broadband technology company Sterlite Technolog...
ID-REDACT® ensures full compliance with the DPDP Act for Indi
Data Safeguard India Pvt Ltd, a wholly-owned subsidiary of Data Safeguard ...
LUMINOUS POWER TECHNOLOGIES PVT. LTD.
LENOVO GROUP LTD.
SAMRIDDHI AUTOMATIONS PVT. LTD.
IBALL WORLDWIDE PVT. LTD.
Technology Icons Of India 2023: Amit Chadha
. An influential leader in the engineering services industry for over ...
Technology Icons Of India 2023: B.V.R. Subrahmanyam
B.V.R. Subrahmanyam belongs to Andhra Pradesh. He is a 1987-batch IAS ...
Technology Icons Of India 2023: Natarajan Chandrasekaran
Natarajan Chandrasekaran is the Chairman of the Board of Tata Sons, th...
PGCIL transforming India with its wide power transmission network
Engaged in power transmission, POWERGRID or PGCIL is a stated owned In...
C-DOT enabling India in indigenous design, development and production of telecom technologies
An autonomous telecom R&D centre of Government of India, Center of Dev...
TCIL continues to strengthen India with its technology expertise
TCIL undertakes consultancy & turnkey projects in the field of Telecom...
SONATA INFORMATION TECHNOLOGY LIMITED
Sonata Software Limited is a leading Modernization engineering company...
INFLOW TECHNOLOGIES PVT. LTD.
Inflow Technologies is a niche player in the IT Infrastructure Distrib...
BEETEL TELETECH LTD.
: Beetel is one of the oldest and most reputed brands in the Industry,...