2016 Indian bank data breach

Last updated

The 2016 Indian bank data breach was reported in October 2016. It was estimated 3.2 million debit cards were compromised. Major Indian banks, among them SBI, HDFC Bank, ICICI, YES Bank and Axis Bank, were among the worst hit. [1] The breach went undetected for months and was first detected after several banks reported fraudulent use of their customers’ cards in China and the United States, while these customers were in India. [2] [3]

This resulted in one of the India's biggest card replacement drives in banking history. The biggest Indian bank, the State Bank of India, announced the blocking and replacement of almost 600,000 debit cards. [4]

An audit performed by SISA Information Security reports that the breach was due to malware injected into the payment gateway network of Hitachi Payment Systems. [5] [6]

See also

Related Research Articles

<span class="mw-page-title-main">State Bank of India</span> Indian public sector bank

State Bank of India (SBI) is an Indian multinational public sector bank and financial services statutory body headquartered in Mumbai, Maharashtra. SBI is the 49th largest bank in the world by total assets and ranked 221st in the Fortune Global 500 list of the world's biggest corporations of 2020, being the only Indian bank on the list. It is a public sector bank and the largest bank in India with a 23% market share by assets and a 25% share of the total loan and deposits market. It is also the fifth largest employer in India with nearly 250,000 employees. On 14 September 2022, State Bank of India became the third lender and seventh Indian company to cross the 5-trillion market capitalisation on the Indian stock exchanges for the first time.

<span class="mw-page-title-main">ICICI Bank</span> Indian private sector bank

ICICI Bank Limited is an Indian multinational bank and financial services company headquartered in Mumbai. It offers a wide range of banking products and financial services for corporate and retail customers through a variety of delivery channels and specialized subsidiaries in the areas of investment banking, life, non-life insurance, venture capital and asset management.

Modern banking in India originated in the mid of 18th century. Among the first banks were the Bank of Hindustan, which was established in 1770 and liquidated in 1829–32; and the General Bank of India, established in 1786 but failed in 1791.

Life insurance is one of the growing sectors in India since 2000 as Government allowed Private players and FDI up to 26% and recently Cabinet approved a proposal to increase it to 49%. In 1955, mean risk per policy of Indian and foreign life insurers amounted respectively to ₹2,950 & ₹7,859. Life Insurance in India was nationalised by incorporating Life Insurance Corporation (LIC) in 1956. All private life insurance companies at that time were taken over by LIC. In 1993, the Government of India appointed RN Malhotra Committee to lay down a road map for privatisation of the life insurance sector.

HDFC Bank Limited is an Indian banking and financial services company headquartered in Mumbai. It is India's largest private sector bank by assets and world's 10th largest bank by market capitalisation as of April 2021. It is the third largest company by market capitalisation of $127.16 billion on the Indian stock exchanges. It is also the fifteenth largest employer in India with nearly 150,000 employees.

Axis Bank Limited, formerly known as UTI Bank (1993–2007), is an Indian banking and financial services company headquartered in Mumbai, Maharashtra. It sells financial services to large and mid-size companies, SMEs and retail businesses.

<span class="mw-page-title-main">Ibibo</span> Online travel organisation, subsidiary of MakeMyTrip Limited

Ibibo Group is an online Indian travel organisation founded in January 2007 by Ashish Kashyap. The company is a subsidiary of MakeMyTrip (MMT) Limited, which owns a 100% stake in Ibibo Group.

<span class="mw-page-title-main">Yes Bank</span> Indian bank

Yes Bank is an Indian bank headquartered in Mumbai, India and was founded by Rana Kapoor and Ashok Kapoor in 2004.

<span class="mw-page-title-main">Saraswat Co-operative Bank Ltd</span>

Saraswat Co-operative Bank Ltd. is an urban co-operative banking institution, having its headquarters in Mumbai, Maharashtra, India and operating as a co-operative society since 1918. The Founding Members of the society were J.K. Parulkar as chairman, N.B. Thakur as vice-chairman, P.N. Warde as Secretary, and Shivram Gopal Rajadhyaksha as Treasurer.

RuPay(portmanteau of Rupee and Payment) is an Indian multinational financial services and payment service system, conceived and launched by the National Payments Corporation of India (NPCI) in 2012. It was created to fulfil the Reserve Bank of India's (RBI) vision of establishing a domestic, open and multilateral system of payments. RuPay facilitates electronic payment at all Indian banks and financial institutions. NPCI maintains ties with Discover Financial, JCB to enable RuPay card scheme to gain international acceptance.

Dexter is a computer virus or point of sale malware which infects computers running Microsoft Windows and was discovered by IT security firm Seculert, in December 2012. It infects PoS systems worldwide and steals sensitive information such as Credit Card and Debit Card information.

<i>Cobrapost</i> Non-profit Indian news website

Cobrapost is a non-profit Indian news website that was founded in 2005 by Aniruddha Bahal – the co-founder of Tehelka. It is particularly known for its undercover investigative journalism.

<span class="mw-page-title-main">Payments bank</span> New model of banks initiative by Reserve Bank of India

Payments banks are new model of banks, conceptualised by the Reserve Bank of India (RBI), which cannot issue credit. These banks can accept a restricted deposit, which is currently limited to ₹200,000 per customer and may be increased further. These banks cannot issue loans and credit cards. Both current account and savings accounts can be operated by such banks. Payments banks can issue ATM cards or debit cards and provide online or mobile banking. Bharti Airtel set up India's first payments bank, Airtel Payments Bank.

SBI Mutual Fund is an Asset Management Company introduced by State Bank of India (SBI) and incorporated in 1987 with its corporate head office located in Mumbai, India. SBIFMPL is a joint venture between the State Bank of India, an Indian public sector bank, and Amundi, a European asset management company. A shareholder agreement in this regard has been entered on April 13, 2011, between SBI & AMUNDI Asset Management. Accordingly, SBI currently holds 63% stake in SBIFMPL and the 37% stake is held by AMUNDI Asset Management through a wholly owned subsidiary, Amundi India Holding. SBI & AMUNDI Asset Management shall jointly develop the company as an asset management company of international repute by adopting global best practices and maintaining international standards.

<span class="mw-page-title-main">ICICI Prudential Mutual Fund</span>

ICICI Prudential Mutual Fund is an Indian asset management company founded in 1993 as a joint venture between ICICI Bank and Prudential plc. It is the second-largest asset management company in India after the SBI Mutual Fund.

Paytm Payments Bank 509145261 (PPBL) is an Indian payments bank, founded in 2017 and headquartered in Noida and is part of mobile payment company paytm. In the same year, it received the license to run a payments bank from the Reserve Bank of India and was launched in November 2017. In 2021, the bank received a scheduled bank status from the RBI.

ICICI Prudential Life Insurance Company Limited is a life insurance company in India. Established as a joint venture between ICICI Bank Limited and Prudential Corporation Holdings Limited, ICICI Prudential Life is engaged in life insurance and asset management business. In 2016, the company became the first insurance company in India to be listed in the domestic stock exchanges.

Data breach incidences in India were the second highest globally in 2018, according to a report by digital security firm Gemalto. With over 690 million internet subscribers and growing, India has increasingly seen a rise in data breaches both in the private and public sector. This is a list of some of the biggest data breaches in the country.

References

  1. Shukla, Saloni; Bhakta, Pratik (20 October 2016). "3.2 million debit cards compromised; SBI, HDFC Bank, ICICI, YES Bank and Axis worst hit". The Economic Times. Retrieved 2 April 2020.
  2. Gopakumar, Gopika (10 February 2017). "Malware caused India's biggest debit card data breach: Audit report". Livemint. Retrieved 2 April 2020.
  3. Christopher, Nilesh (28 December 2016). "The worst cyber attacks of 2016". The Economic Times. Retrieved 2 April 2020.
  4. Iyer, Satyanarayan (20 October 2016). "Security breach: SBI blocks over 6 lakh debit cards". The Economic Times. Retrieved 2 April 2020.
  5. Mathew, Alex (9 February 2017). "Hitachi Owns Up To Mid-2016 Breach That Compromised 32 Lakh Debit Cards". Bloomberg Quint. Retrieved 2 April 2020.
  6. Ryder, Rodney D.; Madhavan, Ashwin (2019). Cyber Crisis Management: Overcoming the Challenges in Cyberspace. New Delhi: Bloomsbury Publishing. ISBN   978-93-89165-52-4.