SMS Data Leak reports : SBI investigation confirms misconfiguration in the process

Submitted by dhananjay on Fri, 02/01/2019 - 22:38

Share

Mumbai :  TechCrunch first reported about the issue of data leak from a server of SBI late Wednesday. It claimed that a security researcher found unprotected server that granted anyone access to financial information of Bank customer’s. It said, "The server, hosted in a regional Mumbai-based data center, stored two months of data from SBI Quick, a text message and call-based system used to request basic information about their bank accounts by customers of the government-owned State Bank of India (SBI)......But the bank had not protected the server with a password, allowing anyone who knew where to look to access the data ..."

In response to the media reports, SBI issued following response on it official  tiwttier handle '@TheOfficialSBI'. Banks response mentions that it had conducted investigation and denies data breach however acknowledges misconfiguration or lacuna in the Outgoing SMS process which uses services of telecom providers. It also stated that it has rectified it and doing everything possible to ensure no such issue remain in the process.

SBI Release

SBI Release 2

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Angry reactions have been noticed to above release from the Bank on the twitter handle. Some them are captured below.

Users reaction to SBI on twitter

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

User Reactions 2