Mobikwik episode shows how not to secure the digital wallet
Shooting the messenger, the one who raises doubts over data protection, does more harm than good. Cyber security has to be a transparent, cooperative exercise.
There was independent corroboration from the anonymous hacker handle Elliot Alderson and Alon Gal, the CTO of the Israeli Security firm, Hudson Rock who maintained that this was the largest KYC breach in India ever. Recently, security researcher Rajashekhar Rajaharia thought he was doing his duty when twice — on February 26 and March 4 — he tried to draw the attention of the Mobikwik management to what many believe is the largest ever data hack in Indian history. As a provider of a mobile phone-based payment system and digital wallet, Mobikwik deals with millions of customers’ data, including sensitive personal information. All that Rajashekhar wanted was for the company to inform the users of the breach and the steps taken to address the situation. He was responding to a hacker who claimed to have access to more than 100 million cardholder details from the Mobikwik client data. What he was not prepared for was the counterattack by the company who called him “media crazed” and also stated that they would be taking legal action against him.
Soon there was independent corroboration from the anonymous hacker handle Elliot Alderson and Alon Gal, the CTO of the Israeli Security firm, Hudson Rock who maintained that this was the largest KYC breach in India ever. It should have been a bummer for anyone using a Tor browser to surf the dark web that an enormous collection of data including KYC of 3.5 million people, phone numbers and bank details of almost 100 million individuals and, in some cases, even geolocation data has been put up for sale for a measly 1.5 bitcoins or approximately rupees 62 lakh. As more and more users found that their data was available online, the company maintained its brazen stand that no data was leaked from its database and its CEO went on Twitter to harp about the “made in India” mark of the business which had nothing to do with data security. He went on to further claim that the data leak could have happened from some other platforms.The cause for worry also lies in the fact that the anonymous hacker who has posted this data claims that the KYC details were used to successfully take micro loans. In the absence of the company owning up to the data breach and informing all the users whose data has been put out, there can be an avalanche of such micro loans that can be taken out with the burden falling on the user who may not even be aware of the breach.