Bengaluru-based 'JusPay' refutes 10 cr card data breach claim, says only 3.5 cr users' info leaked

Agencies
January 6, 2021

Juspay.jpg

Bengaluru, Jan 6: Bengaluru-based digital payments gateway JusPay on Tuesday clarified that about 3.5 crore records with masked card data and card fingerprint were compromised by a hacker and the claim of 10 crore cardholders' data being affected is “incorrect". Responding to claims made by independent cyber security researcher Rajshekhar Rajaharia on Sunday that data of nearly 10 crore credit and debit card holders in the country is being sold for an undisclosed amount on the Dark Web -- leaked from a compromised server of Juspay, the company said in a fresh statement that none of its merchants and their customers are at any risk.

"The masked card data is used for display purposes on merchant UI and cannot be used for completing a transaction. A part of user metadata in our system which has non-anonymised, plain-text email IDs and phone numbers got compromised," the company informed.

"On August 18, 2020, an unauthorised attempt on our servers was detected and terminated when in progress," it added.

According to JusPay, no full card numbers, order information, card PINs and passwords were leaked.

"We conducted a thorough audit on the day of the incident which confirmed that our 'Secure Data Store' which hosts the 16-digit encrypted card numbers was not accessed and remains secure. The cyberattack was identified in an isolated/separate system," JusPay elaborated.

"We can confirm that the compromised data does not contain any transaction or order information, as the intrusion was terminated before such an access."

Rajaharia had told IANS that the data was being sold on the Dark Web for an undisclosed amount via cryptocurrency Bitcoin.

"For this data, hackers are also contacting via Telegram," he said, adding that if the hackers can find out the Hash algorithm used to generate the card fingerprint, they will be able to decrypt the masked card number.

"In this condition, all 10 crore cardholders are at risk," Rajaharia noted.

JusPay said that it has made significant investments in security and data governance and its policies are aligned to globally accepted data protection standards.

"We did identify gaps in some of the older access keys and moved them to non-access key-based authentication supported by hosting providers. We have also made two-factor authentication (2FA) mandatory for all the tools accessed by our teams," the company said.

According to Saurabh Sharma, Senior Security Researcher (GReAT), Kaspersky (APAC), data leaks due to internal vulnerabilities has become a common instance in India, especially in the last two years.

"Enterprises and institutions have begun to understand the importance of having a strong security framework to save themselves from an external attack by a cybercriminal. However, they tend to overlook the internal vulnerabilities that can prove to be very damaging to their reputation and business if exploited by the bad guys," Sharma told IANS.

Regular network and server evaluation, proactive detection of zero-day vulnerabilities and patching them immediately, launching attractive bug-bounty programmes and promptly informing the users of a potential leak are some of the "mandatory steps that large enterprises and institutions should follow in order to stay away from cybercriminals and save their reputation," he added.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
January 9,2025

Mangaluru: Establishing a Beary Development Corporation is a valid demand, but its implications must be carefully studied, remarked Speaker UT Khader. He proposed forming an expert committee to evaluate the corporation’s potential impact on the Beary community during a district-level conference of the Beary-speaking community, organized by the Akhila Bharata Beary Mahasabha at Kudmul Ranga Rao Town Hall on Wednesday.

Khader expressed concerns over inefficiencies in existing government-established corporations, such as unfilled leadership positions, lack of appointed members, and insufficient funding. “The Beary Development Corporation must avoid similar pitfalls,” he emphasized. He noted that the Minorities Development Corporation already provides various schemes for Beary Muslims, urging a detailed assessment to ensure the new corporation’s funding does not fall short of current provisions, which could disadvantage the community.

Praising the industrious and self-respecting nature of the Beary community, Khader highlighted the respect Beary elders once commanded in villages. He encouraged the youth to uphold this legacy and actively contribute to the community’s progress. Additionally, he commended the Beary youth for their swift and dedicated responses during emergencies, which have garnered widespread recognition.

Khader underscored the importance of unity, cautioning against fostering divisions within the community. He also stressed the critical role of education in development, urging the maintenance of detailed records for SSLC and PUC students to track progress.

The event was presided over by Azeez Baikampadi, president of the Akhila Bharata Beary Mahasabha. Among the dignitaries present were former MLA Mohiudeen Bava and retired police officer GA Bawa. Dr. UT Ifikhar Ali Farid, honorary president of the Akhila Bharata Beary Mahasabha and chairman of the Karnataka State Allied and Healthcare Council, was felicitated during the program.

In notable initiatives, Kanachuru Monu, chairman of Kanachuru Medical College, unveiled the Mahasabha’s new website, while Sheikhabba Karnire of Expertise Company, Jubail, launched an IAS-IPS program aimed at empowering the Beary community.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
January 4,2025

Mangaluru: Dakshina Kannada MP Captain Brijesh Chowta met Union Home Minister Amit Shah in New Delhi on Friday to discuss key issues affecting the security and development of the region. The meeting highlighted several urgent concerns, ranging from counter-terrorism measures to infrastructure upgrades.

During the meeting, Chowta strongly advocated for establishing a National Investigation Agency (NIA) Centre in Mangaluru. He pointed out the city’s vulnerability to threats such as Islamic radicalisation, sleeper cells, and the activities of groups like SDPI and PFI. Citing the unrest during the Citizenship Amendment Act (CAA) protests, Chowta emphasized the ability of radical groups to incite large-scale disruptions. He argued that Mangaluru’s strategic coastal location necessitates an NIA Centre to bolster counter-terrorism operations and ensure regional security.

Chowta also discussed the Indian Coast Guard Academy, sanctioned for Mangaluru in 2020. He highlighted its potential to enhance India’s maritime security through advanced training in coastal defence, disaster response, and surveillance. Situated near the Arabian Sea and Mangalore Port, the academy is strategically positioned to address challenges in regions like Lakshadweep and the Maldives, aligning with India’s geostrategic interests.

The MP proposed the establishment of a Sainik School in Mangaluru to nurture leadership, discipline, and patriotism among local youth. He emphasized that such an institution would not only provide quality education but also act as a feeder for the armed forces, enhancing the region’s defence readiness. Chowta suggested pairing the school with a military installation, further strengthening coastal defence capabilities and supporting national security goals.

Addressing infrastructure, Chowta underscored the need to improve the Mangaluru-Bengaluru railway and road networks. He argued that enhanced connectivity would unlock the region’s economic potential, streamline logistics for New Mangalore Port, and support key industries such as fisheries, agriculture, and manufacturing. Additionally, upgraded infrastructure would boost trade, tourism, and employment opportunities.

On economic development, Chowta urged the revival of cooperative banks under the Ministry of Cooperatives. He proposed increased funding and loan facilities for businesses and farmers to enhance financial inclusion and regional economic stability. Strengthening fisheries cooperatives, he noted, would provide local fishermen with better access to financial services, loans, and insurance, improving productivity and security.

The MP’s discussions reflected a comprehensive vision for balancing security, infrastructure, and economic growth in Dakshina Kannada, aligning with both regional and national priorities.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
January 4,2025

Mangaluru: In a shocking case of fraud, six individuals posing as officials from the Enforcement Directorate (ED) swindled a beedi businessman of Rs 25 to 30 lakh in cash and five mobile phones at Kolnad in Bantwal taluk of Dakshina Kannada on Friday night.

The incident came to light after Mohammed Iqbal, 27, lodged a complaint with the police, stating that his father, a beedi trader, was targeted by the imposters.

According to the complaint, the six accused arrived at the businessman’s residence around 8:10 pm in a car with Tamil Nadu registration plates. Claiming to be ED officials, they announced that they had orders to search the house and began confiscating mobile phones from the family members.

The fraudsters reportedly discovered Rs 25 lakh to Rs 30 lakh in cash, which the businessman had kept aside for business purposes. They claimed that keeping such a large amount was illegal and threatened to arrest him unless he complied. By 10:30 pm, the group left the house, instructing the businessman to submit documents at the ED office in Bengaluru to reclaim the money.

Later, upon discussing the incident with his family, Iqbal realized that the individuals were not ED officials but fraudsters who had impersonated authorities to rob them.

A case has been registered at Vittal Police Station under relevant sections of the Indian Penal Code. An investigation is underway, and the police have promised swift action to apprehend the culprits.

Dakshina Kannada Superintendent of Police Yathish N, along with senior officers, visited the crime scene and assured the family that the perpetrators would be brought to justice at the earliest.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.