HSBC hacked leaked customer data

The international financial institution HSBC said it was violated in October. According to the company, names, addresses, transaction history, account information, and more have leaked.
HSBC
In a Communication [PDF] filed with the state of California, the bank said it was aware that some online accounts were accessed by unauthorized users between Oct. 4 and Oct. 14. The hack affected a fraction of the bank's US customers (less than 1 percent of the US customer base s), according to the company's statements to the BBC, but for now no exact numbers have been released.

Spread names, addresses, birthdates, and account balances, transaction histories, and account numbers.

"HSBC deplores this and takes responsibility for protecting its customers," the bank said in a statement.

We have warned customers whose accounts may have been tampered with, and we offer them a one-time anti-theft service in their transactions.

The hack appears to have been done with brute force attacks. The attackers managed to find out of access using automated methods of checking account credentials.

Bryan Becker, application security researcher at WhiteHat Security Reported:

Σε γενικές γραμμές, οι τράπεζες απαιτούν κάποιον έλεγχο ταυτότητας δύο παραγόντων, και αυτό σταματάει κάθε επίθεση που χρησιμοποιεί credential stuffing. Έτσι έχουμε το ερώτημα: Γιατί δεν χρησιμοποιούσε η HSBC έλεγχο ταυτότητας δύο παραγόντων, ή, αν χρησιμοποιούσε, ποια ήταν η πραγματική αιτία της s?

______________________________

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.083 registrants.

Written by giorgos

George still wonders what he's doing here ...

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).