Security breach: Banks block over 32 lakh debit cards; Finance Ministry seeks report

The finance ministry has sought information about the implication of such security breach from Indian Banks Association.

By: ENS Economic Bureau | Mumbai/ New Delhi | Published:October 21, 2016 2:27 am
atm fraud, india atm fraud, debit card block, debit card recall, sbi debit card, sbi debit card recall According to bankers, the security breach happened through a malware allegedly in the systems of Hitachi Payments Services, which serves a private bank.

Commercial banks have blocked or recalled 32 lakh debit cards of customers as a “precautionary” measure after being informed of potential risks to those cards following a major security breach at a payment services provider that manages ATM network of a private sector bank.

The finance ministry has sought information about the implication of such security breach from Indian Banks Association.

The National Payment Corporation of India (NPCI) said the complaints of fraudulent withdrawal were limited to cards of 19 banks and 641 customers. “The total amount involved is Rs 1.3 crore as reported by various affected banks to NPCI,” AP Hota, MD of NPCI said. State Bank of India has either blocked or is in the process of replacing around 6 lakh debit cards following a malware related to security breach in a private bank’s ATM network. Bank of Baroda, IDBI Bank, Central Bank and Andhra Bank have already replaced their debit cards. ICICI Bank, HDFC Bank and Yes Bank have asked customers to change their ATM pin numbers.

Watch what else is making news

According to bankers, the security breach happened through a malware allegedly in the systems of Hitachi Payments Services, which serves a private bank. However, Loney Antony, managing director, Hitachi Payment Services, said, “We had appointed an external audit agency certified by PCI in the 1st week of September, to check the security of our systems. The interim report published by the audit agency in September, does not suggest any breach/ compromise in our systems. The final report is expected by mid-November.”

“Necessary corrective actions have already been taken and hence there is no reason for bank customers to panic. Advisory issued by NPCI to banks for re-cardification is more as a preventive exercise,” Hota said. There are a total of 712.39 million debit cards all over India as on August 31, 2016, according to RBI data. Hota said the genesis of problem could be traced to complaints from some banks that their customer’s cards were used fraudulently mainly in China and the US while customers were in India. “Apprehending that this could be a case of card data compromise, all the ATMs and PoS terminals in India and three card networks — RuPay, Visa and MasterCard — worked in a collaborative manner in the month of September 2016. It was established through an analysis that there was a possible compromise at one of the payment switch provider’s system. Based on the analysis, NPCI and other schemes identified the period of compromise and the possible card numbers which could have been compromised during that period,” NPCI said.

“All affected banks have been alerted by all card networks that a total card base of about 3.2 million could have been possibly compromised. Out of this 0.6 million are RuPay cards,” Hota said. Based on the advisory issued by NPCI and other schemes, banks have advised their customers to change their debit card PIN.

According to bankers, 90 ATMs were compromised through malware and these ATMs were transmitting debit card data of customers to fraudsters. The data breach took place between May and July, but was discovered only in September and banks decided to proactively change the cards.

According to an ICICI Bank spokesperson, the possible breach of information of debit cards has taken place in the ATM network of another bank. “As a precautionary measure, the PINs of debit cards used at the ATMs of that bank have been changed … we are using our real-time fraud monitoring systems … .”

Yes Bank said it has undertaken a comprehensive review of its ATMs, and there is no evidence of a breach or compromise on its ATMs. “Yes Bank continues to work with relevant stakeholders to ensure utmost safety and security of its ATM network and payment services which are completely safe to use,” Yes Bank MD and CEO Rana Kapoor said.

Mastercard, a payment intermediary, said it was aware of “the data compromise event”. “To be clear, Mastercard’s own systems have not been breached … we are working on the investigations with the regulators, issuers, acquirers, global and local law enforcement agencies and third party payment networks to assess the current situation,” it said.

“NPCI, Mastercard and Visa had informed banks about a potential risk to some cards in India owing to a data breach … SBI has taken precautionary measures and have blocked cards of certain customers identified by the networks,” SBI said. Visa said that “It has been informed that some payment cards in India may have been compromised due to suspected breach of payment systems at a service provider …” Visa does not currently process domestic debit ATM transactions in India.

For all the latest India News, download Indian Express App now

  1. P
    paul
    Apr 25, 2017 at 3:00 pm
    Hack and take money directly from any ATM Machine Vault with the use of ATM Programmed Card which runs in automatic mode. email (paulfranciscardhacker@yandex ) for how to get it and it cost,and how to also hack credit cards and send the money to your self,we are located around the world, these cards works on any ATM machine and it works according to it's activation. ………. EXPLANATION OF HOW THESE CARD WORKS………. You just slot in these card into any ATM Machine and it will automatically bring up a MENU of 1st VAULT #1,000, 2nd VAULT #5,000, RE-PROGRAMMED, EXIT, CANCEL. Just click on either of the VAULTS, and it will take you to another SUB-MENU of ALL, OTHERS, EXIT, CANCEL. Just click on others and type in the amount you wish to withdraw from the ATM and you have it cashed instantly… Done. NOTE: DON’T EVER MAKE THE MISTAKE OF CLICKING THE “ALL” OPTION. BECAUSE IT WILL TAKE OUT ALL THE AMOUNT OF THE SELECTED VAULT. To get the card email (paulfranciscardhacker@yandex )
    Reply
    1. P
      paul
      Apr 25, 2017 at 3:00 pm
      Hack and take money directly from any ATM Machine Vault with the use of ATM Programmed Card which runs in automatic mode. email (paulfranciscardhacker@yandex ) for how to get it and it cost,and how to also hack credit cards and send the money to your self,we are located around the world, these cards works on any ATM machine and it works according to it's activation. ………. EXPLANATION OF HOW THESE CARD WORKS………. You just slot in these card into any ATM Machine and it will automatically bring up a MENU of 1st VAULT #1,000, 2nd VAULT #5,000, RE-PROGRAMMED, EXIT, CANCEL. Just click on either of the VAULTS, and it will take you to another SUB-MENU of ALL, OTHERS, EXIT, CANCEL. Just click on others and type in the amount you wish to withdraw from the ATM and you have it cashed instantly… Done. NOTE: DON’T EVER MAKE THE MISTAKE OF CLICKING THE “ALL” OPTION. BECAUSE IT WILL TAKE OUT ALL THE AMOUNT OF THE SELECTED VAULT. To get the card email (paulfranciscardhacker@yandex )
      Reply
      1. C
        christ ben
        Jan 23, 2017 at 7:34 pm
        Hi, My name Esteve and i just want to share my experience with everyone. I have being hearing about this blank ATM card for a while and i never really paid any interest to it because of my doubts. Until one day i discovered a hacking guy called Wayne. he is really good at what he is doing. Back to the point, I inquired about The Blank ATM Card. If it works or even Exist. They told me Yes and that its a card programmed for om money withdraws without being noticed and can also be used for free online purchases of any kind. This was shocking and i still had my doubts. Then i gave it a try and asked for the card and agreed to their terms and conditions. Hoping and praying it was not a scam. One week later i received my card and tried with the closest ATM machine close to me, It worked like magic. I was able to withdraw up to $3000. This was unbelievable and the happiest day of my life. So far i have being able to withdraw up to $28000 without any stress of being caught. I don't know why i am posting this here, i just felt this might help those of us in need of financial stability. blank Atm has really change my life. If you want to contact call 08142630659 09059882152, Here is the email address , And I believe they will also Change your Life
        Reply
        1. M
          mrs mary
          Feb 9, 2017 at 8:51 am
          I got my already programmed and blanked ATM card to withdraw the maximum of $50,000 daily for a maximum of 20 days. I am so happy about this because i got mine last week and I have used it to get $100,000. MRS MARY is giving out the card just to help the poor. and needy though it is illegal but it is something nice and she is not like other scam pretending to have the blank ATM cards. And no one gets caught when using the card. get yours from her. Just send her an email On
          Reply
          1. M
            mrs mary
            Feb 24, 2017 at 12:09 am
            I got my already programmed and blanked ATM card to withdraw the maximum of $50,000 daily for a maximum of 20 days. I am so happy about this because i got mine last week and I have used it to get $100,000. MRS MARY is giving out the card just to help the poor and needy though it is illegal but it is something nice and she is not like other scam pretending to have the blank ATM cards. And no one gets caught when using the card. get yours from her. Just send her an email On
            Reply
            1. C
              campbell joe
              Jan 26, 2017 at 2:17 pm
              I got my already programmed ATM card to withdraw the maximum of $50,000 daily for a maximum of 30 days. I am so happy about this because i got mine last week and I have used it to get $100,000. MR James Carl is giving out the card just to help the poor and needy. he also advice us to help the needy around us when we get the card so that God will keep blessing all of us. get yours from him now. Just send him an email: or 16026337400
              Reply
              1. M
                Mr Joel
                Feb 10, 2017 at 10:57 pm
                I got my already programmed blank ATM card to withdraw a maximum of $5,000 daily for 30 days. I am so happy about this because i got mine last week and I have used it to get $100,000. Mrs OMON is giving out the card just to help the poor and needy though it is illegal but it is something nice and she is not like other scam pretending to have the blank ATM cards. And no one gets caught when using the card. get yours from her. Just send her an email OR
                Reply
                1. R
                  Roland Mike
                  Feb 26, 2017 at 11:34 pm
                  I got my already programmed and blanked ATM card to withdraw the maximum oflt;br/gt;$5,000 daily for a maximum of 20 days. I am so happy about this because ilt;br/gt;got mine last week and I have used it to get $100,000. ROLAND MIKE islt;br/gt;giving out the card just to help the poor and needy though it is illegallt;br/gt;but it is something nice and he is not like other scam pretending to havelt;br/gt;the blank ATM cards. And no one gets caught when using the card. Get yourslt;br/gt;from him. Just send him an email On:
                  Reply
                  1. S
                    simon
                    Feb 2, 2017 at 3:38 am
                    I got my already programmed and blanked ATM card to withdraw the maximum of $5,000 daily for a maximum of 2 months. I am so happy about this because i got mine last week and I have used it to get $10,000. MR SIMON is giving out thelt;br/gt;card just to help the poor and needy though it is illegal but it is something nice and he is not like other scam pretending to have the blank ATM cards. And no one gets caught when using the card. get yours from him. Just send him an email On
                    Reply
                    1. D
                      D n
                      Oct 23, 2016 at 1:02 pm
                      Indian banks can introduce Debit cards with extra security features and a 2 level security viz pin plus biometric identification. Then frauds will not take place. It may be considered to limit the use of Debit cards only at ATMs owned by the specific bank. This will introduce some difficulty but frauds will be rare. The breaking of the ATMs and carrying them away with the cash by the robbers needs urgent action. If remote, unsecured ATM machines are closed no serious difficulty will arise. Debit card holders should be provided insurance cover for fraudulent transfers. Banks can charge some fees if very necessary.
                      Reply
                      1. S
                        S Subramaniam
                        Oct 21, 2016 at 2:56 am
                        It was in the offing when we go in for large scale online payments without adequate security systems. Why such things do not happen in the most developed countries? Our going for cost-effective systems which compromised the security aspects are the contributory factors. It is a wake up call Government needs to stem the rot before going in for large scale digitisation. Incidentally it would be pertinent to mention that I got a call from 918969181663 for renewal of my ATM Debit card. I refused the services and reported the matter to the Bankers to lodge Police complaint so as to track the Mobile Number and book the culprits. This has also been circulated to my friends. I do hope and wish that the RBI Governor takes note of this seriously and takes corrective/remedial measures expeditiously as its customers are most insecure.
                        Reply
                        1. J
                          john
                          Dec 3, 2016 at 6:20 am
                          INSTEAD OF GETTING A LOANlt;br/gt;Get $5,500 USD every day, for six months!lt;br/gt;lt;br/gt;See how it workslt;br/gt;Do you know you can hack into any ATM machine with a hacked Atm card??lt;br/gt;Make up you mind before applying, straight deal...lt;br/gt;lt;br/gt;Order for a blank Atm card now and get millions within a week!: contact us lt;br/gt;via email address:: lt;br/gt;lt;br/gt;We have specially programmed ATM cards that can be use to hack ATM lt;br/gt;machines, the ATM cards can be used to withdraw at the ATM or swipe, at lt;br/gt;stores and POS. We sell this cards to all our customers and interested lt;br/gt;buyers worldwide, the card has a daily withdrawal limit of $5,500 to $10,000 daily on ATM lt;br/gt;and up to $50,000 spending limit in stores depending on the kind of card lt;br/gt;you order for:: and also if you are in need of any other cyber hack lt;br/gt;services, we are here for you anytime any day.lt;br/gt;lt;br/gt;Here is our price lists for the ATM CARDS:lt;br/gt;lt;br/gt;Cards that withdraw $5,500 per day costs $350 USDlt;br/gt;Cards that withdraw $10,000 per day costs $655 USDlt;br/gt;Cards that withdraw $35,000 per day costs $1,150 USDlt;br/gt;Cards that withdraw $50,000 per day costs $3,800 USDlt;br/gt;Cards that withdraw $100,000 per day costs $7,600 USDlt;br/gt;lt;br/gt;make up your mind before applying, straight deal!!!lt;br/gt;lt;br/gt;The price include shipping fees and charges, order now: contact us via lt;br/gt;email address::
                          Reply
                          1. S
                            Sreeraj Karippala
                            Oct 21, 2016 at 5:11 am
                            In 2013 we introduce a prototype to prevent such attacks(include MitM, MitB, Vishing, Phishing, Skimming) in #StartupVillage. more than two year of research and modifications, after the positive feedback from common people, technical experts, cyber security experts currently it reach to a reasonable solution.lt;br/gt;lt;br/gt;yesterday we officially meet a private bank’s IT head who is only one who give us a chance to meet people startup like us. he likes our solution and he is checking its feasibility.lt;br/gt;lt;br/gt;Normally nationalised bank even ready give a replay to us but SBI response us but in a strange way. we still don’t know why the respond like that. i sent a proper replay but nothing get back until today. lt;br/gt;lt;br/gt;we don’t like to make any damage to their name. but we like to say, if our banks are adoption new technology like this we are going to loss our money very soon. lt;br/gt;lt;br/gt;we need to go #BackToCheckBook until a sufficient technology came.lt;br/gt;lt;br/gt;More than business our banking is lies on trust, don’t break it, probably it won’t get back.lt;br/gt;lt;br/gt;i hope banks will be consider startup like us on recent scenarios.
                            Reply
                            1. Load More Comments