HSBC hacked leaked customer data

The international financial institution HSBC said it was violated in October. According to the company, names, addresses, transaction history, account information, and more have leaked.
HSBC
In a Communication [PDF] filed in the State of California, the stated that it was aware that some online accounts were accessed by unauthorized users from October 4 to 14. The hack affected a fraction of the bank's US customers (less than 1 percent of the US customer base s), according to the company's statements to the BBC, but for now no exact numbers have been released.

Spread names, addresses, birthdates, and account balances, transaction histories, and account numbers.

"HSBC deplores this and takes responsibility for protecting its customers," the bank said in a statement.

We have warned customers whose accounts may have been subject to unauthorized access and are offering them a year of monitoring their transactions a theft protection.

The hack seems to have been done with brute force attacks. Attackers managed to find passwords using automated account credentials.

Bryan Becker, Application Security Researcher at WhiteHat Reported:

In general, banks require a two-factor authentication, and this stops any attack using credential stuffing. So we have the question: Why did HSBC not use two-factor authentication, or, if it was using, what was the real cause of the violation?

______________________________

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.

Written by giorgos

George still wonders what he's doing here ...

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).