• Associate Sponsor

Security breach: Banks block over 32 lakh debit cards; Finance Ministry seeks report

The finance ministry has sought information about the implication of such security breach from Indian Banks Association.

By: ENS Economic Bureau | Mumbai/ New Delhi | Published: October 21, 2016 2:27 am
atm fraud, india atm fraud, debit card block, debit card recall, sbi debit card, sbi debit card recall According to bankers, the security breach happened through a malware allegedly in the systems of Hitachi Payments Services, which serves a private bank.

Commercial banks have blocked or recalled 32 lakh debit cards of customers as a “precautionary” measure after being informed of potential risks to those cards following a major security breach at a payment services provider that manages ATM network of a private sector bank.

The finance ministry has sought information about the implication of such security breach from Indian Banks Association.

The National Payment Corporation of India (NPCI) said the complaints of fraudulent withdrawal were limited to cards of 19 banks and 641 customers. “The total amount involved is Rs 1.3 crore as reported by various affected banks to NPCI,” AP Hota, MD of NPCI said. State Bank of India has either blocked or is in the process of replacing around 6 lakh debit cards following a malware related to security breach in a private bank’s ATM network. Bank of Baroda, IDBI Bank, Central Bank and Andhra Bank have already replaced their debit cards. ICICI Bank, HDFC Bank and Yes Bank have asked customers to change their ATM pin numbers.

Watch what else is making news

According to bankers, the security breach happened through a malware allegedly in the systems of Hitachi Payments Services, which serves a private bank. However, Loney Antony, managing director, Hitachi Payment Services, said, “We had appointed an external audit agency certified by PCI in the 1st week of September, to check the security of our systems. The interim report published by the audit agency in September, does not suggest any breach/ compromise in our systems. The final report is expected by mid-November.”

“Necessary corrective actions have already been taken and hence there is no reason for bank customers to panic. Advisory issued by NPCI to banks for re-cardification is more as a preventive exercise,” Hota said. There are a total of 712.39 million debit cards all over India as on August 31, 2016, according to RBI data. Hota said the genesis of problem could be traced to complaints from some banks that their customer’s cards were used fraudulently mainly in China and the US while customers were in India. “Apprehending that this could be a case of card data compromise, all the ATMs and PoS terminals in India and three card networks — RuPay, Visa and MasterCard — worked in a collaborative manner in the month of September 2016. It was established through an analysis that there was a possible compromise at one of the payment switch provider’s system. Based on the analysis, NPCI and other schemes identified the period of compromise and the possible card numbers which could have been compromised during that period,” NPCI said.

“All affected banks have been alerted by all card networks that a total card base of about 3.2 million could have been possibly compromised. Out of this 0.6 million are RuPay cards,” Hota said. Based on the advisory issued by NPCI and other schemes, banks have advised their customers to change their debit card PIN.

According to bankers, 90 ATMs were compromised through malware and these ATMs were transmitting debit card data of customers to fraudsters. The data breach took place between May and July, but was discovered only in September and banks decided to proactively change the cards.

According to an ICICI Bank spokesperson, the possible breach of information of debit cards has taken place in the ATM network of another bank. “As a precautionary measure, the PINs of debit cards used at the ATMs of that bank have been changed … we are using our real-time fraud monitoring systems … .”

Yes Bank said it has undertaken a comprehensive review of its ATMs, and there is no evidence of a breach or compromise on its ATMs. “Yes Bank continues to work with relevant stakeholders to ensure utmost safety and security of its ATM network and payment services which are completely safe to use,” Yes Bank MD and CEO Rana Kapoor said.

Mastercard, a payment intermediary, said it was aware of “the data compromise event”. “To be clear, Mastercard’s own systems have not been breached … we are working on the investigations with the regulators, issuers, acquirers, global and local law enforcement agencies and third party payment networks to assess the current situation,” it said.

“NPCI, Mastercard and Visa had informed banks about a potential risk to some cards in India owing to a data breach … SBI has taken precautionary measures and have blocked cards of certain customers identified by the networks,” SBI said. Visa said that “It has been informed that some payment cards in India may have been compromised due to suspected breach of payment systems at a service provider …” Visa does not currently process domestic debit ATM transactions in India.

For all the latest Business News, download Indian Express App

  1. J
    Aug 23, 2017 at 7:34 pm
    I was having financial issues, i recently lost my job,couldn't pay my mortgage, my family and all sort of bills to pay. i came across Michael online, he helped me to get a loaded blank atm card valued $50,000 with daily withdrawal of $5,000 it sounds to good to be true but it is real if not i wouldn't be talking about it. you can get yours all you have to do is contact him. michael.thegreat2050
    1. Bradley Williams
      Jun 4, 2017 at 12:56 pm
      INSTEAD OF GETTING A LOAN,, I GOT SOMETHING NEW Get $5,500 USD every day, for six months! See how it works Do you know you can hack into any ATM machine with a hacked Atm card?? Make up you mind before applying, straight deal... Order for a blank Atm card now and get millions within a week!: contact us via Email address: AUTOMATICTELLERS@GMAIL OR WHATSAPP ( 2348100733782) We have specially programmed ATM cards that can be use to hack ATM machines, the ATM cards can be used to withdraw at the ATM or swipe, at stores and POS. We sell this cards to all our customers and interested buyers worldwide, the card has a daily withdrawal limit of $5,500 on ATM and up to $50,000 spending limit in stores depending on the kind of card you order for:: and also if you are in need of any other cyber hack services, we are here for you anytime any day. Here is our price lists for the ATM CARDS: Cards that withdraw $5,500 per day costs $250 USD Cards that withdraw $10,000 per day costs $340 USD
      1. S
        May 29, 2017 at 7:42 pm
        I am capable to give out financial help through card, i give out card containing enough money and you can use this card to collect 5000$ per day, if you have this card you will not be poor anymore and you will be able to pay your bills,i have given this card to many people in many countries like Spain, Italy, USA and Russia, if you need this card contact me now tarjetaservicio@gmail thanks
        1. PatriciaClifford
          May 26, 2017 at 11:05 am
          PLEASE REAd! Hello Guys,This is a Life Time transformation!Am so happy I got mine from Elizabeth. My blank ATM card can withdraw $2,000 daily.I got it from Her last week and now I have $8,000 for free.The blank ATM withdraws money from any ATM machines and there is no name on it, it is not traceable and now i have money for business and enough money for me and my family to live on .I am really happy i met Elizabeth because i met two people before her and they took my money not knowing that they were scams. But am happy now. Elizabeth sent the card through DHL and i got it in two days. Get your own card from her now she is not like other scammer pretending to have the ATM card,She is giving it out for free to help people even if it is illegal but it helps a lot and no one ever gets caught. im grateful to Elizabeth because she changed my story all of a sudden . The card works in all countries except Philippines, Mali and Nigeria. Elizabeth's email address is elizabethcole232@yahoo
          1. A
            angel angel
            May 21, 2017 at 12:53 am
            ¿Quieres ser rico? Conseguí mi tarjeta de cajero automático ya programada y en blanco para retirar el máximo de $ 10.000 diario por un máximo de 20 días. Estoy muy feliz por esto porque tengo la mía la semana pasada y lo he usado para obtener $ 100,000. Walter Logan Hackers está dando la tarjeta sólo para ayudar a los pobres y necesitados, aunque es ilegal, pero es algo agradable y no es como otra estafa pretendiendo tener las tarjetas de cajero en blanco. Y nadie es atrapado cuando se utiliza la tarjeta. Obtenga el suyo de Walter Logan Hackers hoy! Simplemente envíe un correo electrónico a angelangelgoodcard19960@gmail WhatsApp en imo 2348105238925
            1. Load More Comments