• Home
  • Blog
  • Android
  • Cars
  • Gadgets
  • Gaming
  • Internet
  • Mobile
  • Sci-Fi
Tech News, Magazine & Review WordPress Theme 2017
  • Home
  • Blog
  • Android
  • Cars
  • Gadgets
  • Gaming
  • Internet
  • Mobile
  • Sci-Fi
No Result
View All Result
  • Home
  • Blog
  • Android
  • Cars
  • Gadgets
  • Gaming
  • Internet
  • Mobile
  • Sci-Fi
No Result
View All Result
Blog - Creative Collaboration
No Result
View All Result
Home Internet

Data breach on Indian mobile payment app BHIM exposes 7 million records

June 2, 2020
Share on FacebookShare on Twitter

A data breach on a government-promoted payments app BHIM in India has resulted in some highly sensitive personal data of over 7 million people getting exposed. The vulnerability and the data exposure was brought to the fore by an Israeli cybersecurity company. 

The CSC BHIM website is used for financial transactions through a unified payment interface (UPI) as part of the federal government’s digital access initiatives in the villages. The BHIM project was initially launched to drive digital payments for merchants across rural India. The app was developed by the National Payment Corporation of India, a state-owned enterprise. 

Israeli cybersecurity agency vpnMentor, which found the data breach, said more than 400 GB of user data was compromised and these included details of Aadhar registrations, caste certificates and other personal data that could be used to identify people and businesses.  

The company claimed that the hacker would now possess complete data of users and likened it to gaining access to the data infrastructure of a bank with all user account information. It said the vulnerability was first detected on April 23 and was reportedly fixed nearly a month later on May 22. 

Though there is no evidence to point out that the BHIM app itself was leaking data or that the UPI system was insecure, the security agency says that some more research is required to highlight the vulnerabilities so that future threats can be avoided. 

Ironically, news of the breach comes when #CSCSocialMediaDay has been trending on Twitter. 

#CSCSocialMediaDay #CSCSocialMediaDayCSC is my identity. It gives me everything.I am proud to be a part of CSC.@CSCegov_ @dintya15 @wifichoupal @CSCMaharashtra @CSCNashik @rsprasad @Swapnil66864291 @maheshkolte15 @Gaurav08Pawar pic.twitter.com/lYwgbOr5cdJune 1, 2020

In the report, vpmMentor says the data collected for deploying the BHIM app was stored on a mis-configured Amazon Web Services S3 bucket that was accessible publicly. This, the agency said, is a common error that many companies do when setting up their cloud systems. The data that lay unsecured amounted to 409 GB and contained information about individuals and several merchants. 

The UPI payment system is similar to a bank account and is valuable to hackers in general. It gives them access to vast amounts of information about a person’s finances and bank accounts, which can then be used to illegally access them and make fraudulent  transactions. 

The statement from vpnMentor research team said it discovered the misconfiguration in CSC’s S3 bucket as part of a huge web mapping project. “Our researchers use port scanning to examine particular IP blocks and test different systems for weaknesses or vulnerabilities. They examine each weakness for any data being exposed,” the report said.

This is not the first time that vulnerability issues have been by third-parties around apps in India. The Covid-19 tracing app Aarogya Setu saw several such reports including an ethical hacker in Bangalore who claimed he broke into the system in a very short time. The administration took cognisance of these reports and offered a bugs bounty program after sharing the code base on public domains like GitHub. 

Next Post

The rocket science behind the SpaceX astronaut launch

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

No Result
View All Result

Recent Posts

  • Crimson Desert on PS5 Pro: This Is How Good It Looks And How Well It Runs
  • Samsung Galaxy S26 Ultra torn apart by YouTuber. This is what he found.
  • This YouTube web tool brings back the magic of cable channel surfing
  • MacBook Neo: Here’s everything reviewers didn’t like
  • Bumble to test AI-powered dating experience

Recent Comments

    No Result
    View All Result

    Categories

    • Android
    • Cars
    • Gadgets
    • Gaming
    • Internet
    • Mobile
    • Sci-Fi
    • Home
    • Shop
    • Privacy Policy
    • Terms and Conditions

    © CC Startup, Powered by Creative Collaboration. © 2020 Creative Collaboration, LLC. All Rights Reserved.

    No Result
    View All Result
    • Home
    • Blog
    • Android
    • Cars
    • Gadgets
    • Gaming
    • Internet
    • Mobile
    • Sci-Fi

    © CC Startup, Powered by Creative Collaboration. © 2020 Creative Collaboration, LLC. All Rights Reserved.

    Get more stuff like this
    in your inbox

    Subscribe to our mailing list and get interesting stuff and updates to your email inbox.

    Thank you for subscribing.

    Something went wrong.

    We respect your privacy and take protecting it seriously