This story is from December 20, 2017
Security firm Sisa alerts banks on malware attack
Mumbai: Payment security firm
Speaking to TOI, a Sisa spokesperson said that a malicious script (software code) has been injected into the payment switch application server — the hub which communicates with payment networks. This malicious software is capable of collecting payment card data (including
While the malicious software has been identified, it is not yet clear whether customer accounts have been compromised.
SISA is the payment forensic investigator which investigated India’s largest debit card breach last year — which forced one of the biggest debit card reissuance in the country. “We have released this advisory in the interest of proactively securing the payment card industry based on recent findings by SISA PFI (Payment card industry Forensic Investigation) Lab,” said a company spokesperson.
In India, banks are not bound to disclose to either the public or their customers about data breach. Lenders do not even report data breaches to peer banks. However, two years ago the RBI had made it mandatory to report such breaches. Also, the central bank, without using names, issues a warning to other banks. The RBI also mandates banks to adopt global payment card industry data security standards (PCI-DSS). SISA, which audits the
“In the light of the recent finding, SISA suggests to the industry to implement internationally renowned Security Standards like PCI-DSS and PA (payment application)-DSS. SISA also urge Regulators and Government of India to mandate these security standard to be followed religiously,” the statement said.
Sisa
has issued an advisory to all banks and payment processors after it discovered that hackers had managed to insert malicious software into the payment switch server of an unnamed bank. The advisory is in the nature of a warning to other banks to reset passwords for employees with access to payment servers and to use two-factor authentication for providing access.card number
, expiry date,CVV
and other customer information). The hacker can then use this information to clone cards and conduct transactions. The malicious software also enables transactions by sending fake response to the payment network in respect of the card. The fake responses ensures that no details of the incoming transaction request or outgoing transaction response are logged in the switch application logs.While the malicious software has been identified, it is not yet clear whether customer accounts have been compromised.
SISA is the payment forensic investigator which investigated India’s largest debit card breach last year — which forced one of the biggest debit card reissuance in the country. “We have released this advisory in the interest of proactively securing the payment card industry based on recent findings by SISA PFI (Payment card industry Forensic Investigation) Lab,” said a company spokesperson.
In India, banks are not bound to disclose to either the public or their customers about data breach. Lenders do not even report data breaches to peer banks. However, two years ago the RBI had made it mandatory to report such breaches. Also, the central bank, without using names, issues a warning to other banks. The RBI also mandates banks to adopt global payment card industry data security standards (PCI-DSS). SISA, which audits the
PCI-DSS
compliance of banks, has said that some banks are using simple passwords for employees to log into payment servers and has called for two-factor authentication.“In the light of the recent finding, SISA suggests to the industry to implement internationally renowned Security Standards like PCI-DSS and PA (payment application)-DSS. SISA also urge Regulators and Government of India to mandate these security standard to be followed religiously,” the statement said.
Popular from Business
- Adani setback 2.0: US indictment sends shockwaves across India and world
- Stock market today: BSE Sensex ends 1,961 points up; Nifty50 above 23,900 - top reasons bulls are back
- Now, airlines to provide beverages, snacks or meals to passengers of delayed flights
- Elon Musk takes witty dig at Jaguar's new logo, asks 'Do you sell cars?' - here's how Jaguar responded
- US indicts Gautam Adani for bribing officials in India, misleading investors; issues arrest warrants
end of article
Trending Stories
- Will banks open only for 5 days a week? Here’s what you should know about IBA’s proposal
- India set to be third largest economy, says S&P Global
- Dalal Street bull run continues! BSE Sensex crosses 69,000 for the first time; Nifty above 20,800
- Byju’s reduces notice period for employees as troubles mount
03:08 Sensex surges over 900 points, Nifty above 20,550 as BJP state election wins bolster Modi's Lok Sabha 2024 prospects- UltraTech to buy building materials business of Kesoram in 7,600 crore deal
- Tata Technologies stock debuts at a bumper 140% premium; share price at Rs 1200 on BSE
Visual Stories
- NEET UG 2024 result awaited: Top 10 NIRF-ranked medical colleges of India
- 7 New Expected Bullet Train Routes in India
- 10 Upcoming High-Speed Expressways That Will Change Highway Travel In India
- 8 Transformational Indian Railways Projects You Shouldn’t Miss
- Why Sensex, Nifty50 Hit New Highs, M-Cap At $5 Trillion: Top Reasons
TOP TRENDS
UP NEXT
Start a Conversation
Post comment