HSBC hacked leaked customer data

Ο χρηματοπιστωτικός οργανισμός HSBC ανέφερε ότι παραβιάστηκε τον Οκτώβριο. Σύμφωνα με την εταιρεία names, addresses, transaction history, account information and more.
HSBC
In a Communication [PDF] filed in her state , η τράπεζα δήλωσε ότι γνώριζε ότι μερικοί διαδικτυακοί λογαριασμοί προσεγγίστηκαν από μη εξουσιοδοτημένους χρήστες από 4 έως 14 Οκτωβρίου. Το hack πρόσβαλε ένα τμήμα των Αμερικανών πελατών της τράπεζας (λιγότερο από 1 τοις εκατό της αμερικανικής πελατειακής βάσης της), σύμφωνα με δηλώσεις της εταιρείας στο BBC, αλλά προς το παρόν δεν έχουν κυκλοφορήσει ακριβείς αριθμοί.

Spread names, addresses, birthdates, and account balances, transaction histories, and account numbers.

"HSBC deplores this and takes responsibility for protecting its customers," the bank said in a statement.

We have warned customers whose accounts may have been tampered with, and we offer them a one-time anti-theft service in their transactions.

The hack appears to have been done with brute force attacks. Attackers managed to discover passwords using automated methods of account credentials.

Bryan Becker, application security researcher at WhiteHat Security Reported:

In general, banks require a two-factor authentication, and this stops any attack using credential stuffing. So we have the question: Why did HSBC not use two-factor authentication, or, if it was using, what was the real cause of the violation?

______________________________

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.

Written by giorgos

George still wonders what he's doing here ...

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).