Bengaluru-based 'JusPay' refutes 10 cr card data breach claim, says only 3.5 cr users' info leaked

Agencies
January 6, 2021

Juspay.jpg

Bengaluru, Jan 6: Bengaluru-based digital payments gateway JusPay on Tuesday clarified that about 3.5 crore records with masked card data and card fingerprint were compromised by a hacker and the claim of 10 crore cardholders' data being affected is “incorrect". Responding to claims made by independent cyber security researcher Rajshekhar Rajaharia on Sunday that data of nearly 10 crore credit and debit card holders in the country is being sold for an undisclosed amount on the Dark Web -- leaked from a compromised server of Juspay, the company said in a fresh statement that none of its merchants and their customers are at any risk.

"The masked card data is used for display purposes on merchant UI and cannot be used for completing a transaction. A part of user metadata in our system which has non-anonymised, plain-text email IDs and phone numbers got compromised," the company informed.

"On August 18, 2020, an unauthorised attempt on our servers was detected and terminated when in progress," it added.

According to JusPay, no full card numbers, order information, card PINs and passwords were leaked.

"We conducted a thorough audit on the day of the incident which confirmed that our 'Secure Data Store' which hosts the 16-digit encrypted card numbers was not accessed and remains secure. The cyberattack was identified in an isolated/separate system," JusPay elaborated.

"We can confirm that the compromised data does not contain any transaction or order information, as the intrusion was terminated before such an access."

Rajaharia had told IANS that the data was being sold on the Dark Web for an undisclosed amount via cryptocurrency Bitcoin.

"For this data, hackers are also contacting via Telegram," he said, adding that if the hackers can find out the Hash algorithm used to generate the card fingerprint, they will be able to decrypt the masked card number.

"In this condition, all 10 crore cardholders are at risk," Rajaharia noted.

JusPay said that it has made significant investments in security and data governance and its policies are aligned to globally accepted data protection standards.

"We did identify gaps in some of the older access keys and moved them to non-access key-based authentication supported by hosting providers. We have also made two-factor authentication (2FA) mandatory for all the tools accessed by our teams," the company said.

According to Saurabh Sharma, Senior Security Researcher (GReAT), Kaspersky (APAC), data leaks due to internal vulnerabilities has become a common instance in India, especially in the last two years.

"Enterprises and institutions have begun to understand the importance of having a strong security framework to save themselves from an external attack by a cybercriminal. However, they tend to overlook the internal vulnerabilities that can prove to be very damaging to their reputation and business if exploited by the bad guys," Sharma told IANS.

Regular network and server evaluation, proactive detection of zero-day vulnerabilities and patching them immediately, launching attractive bug-bounty programmes and promptly informing the users of a potential leak are some of the "mandatory steps that large enterprises and institutions should follow in order to stay away from cybercriminals and save their reputation," he added.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
May 3,2024

Mangaluru, May 3: The Mangaluru City Corporation will resort to water rationing from May 5 as the Thumbe vented dam, which supplies drinking water to the city, is facing a shortage in water storage.

Instead of daily supply, water will be supplied on alternate days, the Executive Engineer (Water Supply) at the corporation said in a release.

The release said that water will be supplied to Mangaluru City North on May 5. There will be no water supply to Mangaluru City North on May 6. Instead water will be supplied to Mangaluru City South on May 6. Likewise the supply on alternate days will continue.

The inflow in the Netravathi has stopped, the release said, requesting people to cooperate with the corporation and not waste water for washing vehicles and other purposes.

An engineer at the corporation said that water level at the dam stood at 4.27 m on Wednesday against the full storage level of 6 m. If water is supplied daily to the entire city (Mangaluru City North and Mangaluru City South) the existing storage will last only for 16 days, the engineer said. Hence the decision to supply water on alternate days has been taken to supply water till May-end.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
May 14,2024

revanna..jpg

Bengaluru, May 14: JD(S) leader HD Revanna has been released from Parappana Agrahara Jail today, on May 14 after he was granted conditional bail. 

He was granted a conditional bail yesterday by a Bengaluru court in connection with a kidnapping case linked to sexual abuse allegation against him and his son Prajwal.

Revanna was arrested on May 4 by Special Investigative Team (SIT) officials in a kidnapping case registered against him at KR Nagar police station in the city. The case is linked to his son and Hassan MP Prajwal Revanna’s mega sex scam. 

Representing the JD(S) MLA from Holenarsipura, he termed this case a "political conspiracy" against him.

A SIT, constituted by the Karnataka government, is probing the alleged sexual abuse against against HD Revanna and his son Prajwal Revanna.

Prajwal Revanna, the incumbent MP, is seeking another term from Hassan Lok Sabha constituency. The voting for the seat took place on April 26.

Earlier, JD (S) chief HD Kumaraswamy alleged that Karnataka government does not want a fair inquiry.

"They are misusing the office. Nothing is going to happen ultimately. They wanted character assassination of HD Revanna and for that reason, they are using their office," Kumaraswamy told ANI.

Meeting Karnataka Governor Tawara Chanda Gehlot on May 9, a delegation of the Janata Dal (Secular) submitted a memorandum and urged Gehlot to recommend a CBI probe.

Prajwal sill absconding

The JD(S) MP, Prajwal, fled to Germany after Karnataka State Commission for Women Nagalakshmi Chowdhary wrote to Chief Minister Siddaramaiah seeking an investigation into over obscene videos of Prajwal Revanna allegedly sexually abusing several women. He has also skipped summons issued by the SIT to appear before it.

The ‘obscene videos’ involving Prajwal Revanna started making the rounds ahead of the first phase of Lok Sabha elections in Karnataka on April 26, triggering a political slugfest.

A lookout notice against Prajwal Revanna has been issued at all airports in India, along with a Blue Corner notice. A Blue Corner notice issued by Interpol helps countries collect and share information regarding a person's location and their activities as part of a criminal investigation.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
May 3,2024

boat.jpg

Mangaluru: The passenger vessel service between Lakshadweep and Mangaluru has recommenced operations with the arrival of Parali, a high-speed craft, at the Old Mangaluru Port on Thursday, May 2 

With 160 passengers on board, along with a pilot, a ship engineer, an assistant, and eight labourers, the arrival of the vessel brings hopes of reinstating this vital transportation link.

The passengers were welcomed by Congress brass. The vessels that used to arrive before the Covid-19 pandemic took 13 hours to reach Mangaluru from Lakshadweep. However, the introduction of the high-speed craft, Parali, has reduced the travel time to approximately seven hours, said Abubakar Ashraf Bengre.

Bengre is part of a team that has been instrumental in liaising with the authorities of both Lakshadweep and Karnataka to facilitate the revival of this service. He told reporters that the service would bring better economic activity to Mangaluru. 

Over recent months, discussions have been held with Hamdullah Sayeed, president, Lakshadweep Congress Committee, as well as Karnataka Speaker UT Khader and district minister Dinesh Gundu Rao, to garner support for the reintroduction of the service.

The passengers who arrived mostly sought medical treatment, went shopping or met relatives here. They said that they traveled for Rs 450. Former MLA J R Lobo said that they will urge the government to ensure regular vessel services continue.

The passenger service was discontinued due to a lack of demand, it is learnt. In the year 2018-19, 4,955 passengers embarked and 7,422 disembarked from the Old Mangaluru Port. Subsequently, the figures declined to 3,779 (embarked) and 2,294 (disembarked) in 2019-20. The numbers further plummeted to 561 (embarked) and 19 (disembarked) in 2020-21, leading to the suspension of the service.

At present, the administration of the Union Territory of Lakshadweep has released a schedule for high-speed craft movement from April 29 to May 5.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.