Bengaluru-based 'JusPay' refutes 10 cr card data breach claim, says only 3.5 cr users' info leaked

Agencies
January 6, 2021

Juspay.jpg

Bengaluru, Jan 6: Bengaluru-based digital payments gateway JusPay on Tuesday clarified that about 3.5 crore records with masked card data and card fingerprint were compromised by a hacker and the claim of 10 crore cardholders' data being affected is “incorrect". Responding to claims made by independent cyber security researcher Rajshekhar Rajaharia on Sunday that data of nearly 10 crore credit and debit card holders in the country is being sold for an undisclosed amount on the Dark Web -- leaked from a compromised server of Juspay, the company said in a fresh statement that none of its merchants and their customers are at any risk.

"The masked card data is used for display purposes on merchant UI and cannot be used for completing a transaction. A part of user metadata in our system which has non-anonymised, plain-text email IDs and phone numbers got compromised," the company informed.

"On August 18, 2020, an unauthorised attempt on our servers was detected and terminated when in progress," it added.

According to JusPay, no full card numbers, order information, card PINs and passwords were leaked.

"We conducted a thorough audit on the day of the incident which confirmed that our 'Secure Data Store' which hosts the 16-digit encrypted card numbers was not accessed and remains secure. The cyberattack was identified in an isolated/separate system," JusPay elaborated.

"We can confirm that the compromised data does not contain any transaction or order information, as the intrusion was terminated before such an access."

Rajaharia had told IANS that the data was being sold on the Dark Web for an undisclosed amount via cryptocurrency Bitcoin.

"For this data, hackers are also contacting via Telegram," he said, adding that if the hackers can find out the Hash algorithm used to generate the card fingerprint, they will be able to decrypt the masked card number.

"In this condition, all 10 crore cardholders are at risk," Rajaharia noted.

JusPay said that it has made significant investments in security and data governance and its policies are aligned to globally accepted data protection standards.

"We did identify gaps in some of the older access keys and moved them to non-access key-based authentication supported by hosting providers. We have also made two-factor authentication (2FA) mandatory for all the tools accessed by our teams," the company said.

According to Saurabh Sharma, Senior Security Researcher (GReAT), Kaspersky (APAC), data leaks due to internal vulnerabilities has become a common instance in India, especially in the last two years.

"Enterprises and institutions have begun to understand the importance of having a strong security framework to save themselves from an external attack by a cybercriminal. However, they tend to overlook the internal vulnerabilities that can prove to be very damaging to their reputation and business if exploited by the bad guys," Sharma told IANS.

Regular network and server evaluation, proactive detection of zero-day vulnerabilities and patching them immediately, launching attractive bug-bounty programmes and promptly informing the users of a potential leak are some of the "mandatory steps that large enterprises and institutions should follow in order to stay away from cybercriminals and save their reputation," he added.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
January 2,2025

cars.jpg

Mangaluru, Jan 2: The coastal city of Mangaluru witnessed yet another alarming car fire incident last evening, marking the latest in a series of similar mishaps in recent months. Fortunately, quick action by the driver and passengers prevented any injuries.

On January 1, a moving Volkswagen car caught fire on the road leading to the helipad at Maryhill. The passengers noticed flames emanating from the front of the vehicle. Acting promptly, the driver pulled over, and all four occupants exited safely.

Local residents attempted to douse the flames using water, and personnel from the Kadri fire service soon arrived to manage the situation. Despite their efforts, the car's engine was completely destroyed.

This incident adds to a growing list of car fire cases reported in Mangaluru recently:

December 16, 2024: A Hyundai car caught fire near City Centre Mall. The driver narrowly escaped.

November 15, 2024: A car was gutted within minutes near Kadri police station, though the driver escaped unharmed.

November 10, 2024: A Maruti 800 waiting at a petrol station caught fire and was completely burnt.

September 28, 2024: A parked BMW at Adyar was destroyed in a fire.

September 5, 2024: Another BMW caught fire near NITK.

In all these incidents, timely evacuation ensured that no injuries were reported. However, the frequency of such cases raises serious concerns about vehicle safety and the need for preventive measures.

Authorities and vehicle manufacturers must investigate the underlying causes of these fires to prevent future occurrences. Public awareness about vehicle maintenance and safety measures is also critical to avert such mishaps.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
January 14,2025

ashokavijayendra.jpg

Bengaluru: The BJP on Tuesday accused the police of "framing" an innocent person in the cow attack case in Chamarajapet here and demanded a fair investigation into the incident.

Sheikh Nasru (30), a native of Champaran in Bihar, has been arrested for allegedly slashing the udders of three cows on Sunday.

The matter escalated into a communal controversy after the saffron party threatened to observe 'Black Sankranti' if the culprits were not arrested before the festival.

The party has since emphasised that the actual perpetrators must be apprehended.

Addressing media here, BJP state president B Y Vijayendra said, "There are claims that an innocent man has been falsely implicated and is being projected as the culprit."

Leader of Opposition R Ashoka also raised doubts about the investigation, questioning how a mentally unstable man could work at the firm for a decade.

Ashoka noted that the incident occurred at the veterinary hospital, which spans four acres.

He alleged that the hospital was recently declared Waqf property and claimed that Karna, the owner of the injured cattle, had opposed the Waqf Board’s decision, suggesting this opposition might have led to the incident.

The party leaders led by Vijayendra and Ashoka celebrated 'Sankranti' by offering special prayers to cows at the spot where the attack took place.

Meanwhile, state Home Minister G Parameshwara dismissed the opposition charges and said the police were investigating the case without any bias.

"If the investigation reveals the involvement of more people, then police will not spare them," he told reporters here.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
January 8,2025

beaches.jpg

Mangaluru, Jan 8: The serene beaches near Kulai Jetty under the limits of Surathkal police station turned into a scene of tragedy on Wednesday, January 8, as a group of four close friends saw their day of joy morph into heartbreak. 

Three young men lost their lives in the unforgiving waves, while one narrowly escaped death, saved by the heroic efforts of local fishermen.

The victims have been identified as: 

M. S. Manjunath (31), son of Shivlingappa, hailing from Upparigenahalli, Chitradurga district.

Shivakumar (30) from Shivamogga district.

Satyavelu (30) from JP Nagar, Bengaluru.

The sole survivor, Parameshwara (30), from Hangarga, Bidar district, now carries the weight of a harrowing ordeal and the devastating loss of his three closest friends.

These young men, all students of AMC Engineering College in Bengaluru, had embarked on a trip meant to create memories of joy and camaraderie. Driving overnight from Bengaluru, they reached Mangaluru on Wednesday morning. After breakfast at a local eatery, the group decided to visit the picturesque Kulai Jetty, seeking solace and adventure in the sea.

But their joyful outing took a tragic turn. While playing in the water, the four were caught in strong currents. Despite the swift intervention of local fishermen, only Parameshwara could be rescued in time. The lifeless bodies of Manjunath, Shivakumar, and Satyavelu were later found on the right side of the jetty, their dreams and futures cruelly cut short.

The Surathkal police, alerted to the incident, promptly arrived at the scene and began their investigation. The bodies were transported to AJ Hospital for post-mortem examinations, leaving their families and friends to grapple with the enormity of their loss.

A case has been registered at Surathkal Police Station. This incident serves as a stark reminder of the unpredictable and dangerous nature of the sea, urging visitors to prioritize safety above all else.

What was meant to be a day of joy has left a void that can never be filled, as three grieving families now face the unbearable pain of losing their loved ones.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.