No security lapses found after investigating alleged breach: Paytm Mall

The clarification came after US-based cyber research firm Cyble had said a hacker group with the alias 'John Wick' was able to gain unrestricted access to Paytm Mall's databases

paytm
The company spokesperson added that the company invests heavily in data security, and also has a Bug Bounty programme under which it rewards responsible disclosure of any security risks
Press Trust of India New Delhi
2 min read Last Updated : Aug 30 2020 | 10:49 PM IST

The e-commerce unit of payment solutions provider Paytm, Paytm Mall, on Sunday said it has not found any security lapses yet after investigating claims of a possible hack and data breach.

The clarification came after US-based cyber research firm Cyble had said a hacker group with the alias 'John Wick' was able to gain unrestricted access to Paytm Mall's databases.

"We would like to assure that all user, as well as company data, is completely safe and secure... We have been investigating the claims of a possible hack and data breach, and haven't found any security lapses yet," a Paytm Mall spokesperson said in a statement.

The spokesperson added that the company invests heavily in data security, and also has a Bug Bounty programme under which it rewards responsible disclosure of any security risks.
 

"We extensively work with the security research community and safely resolve security anomalies," the spokesperson said.

Cyble, in a blog, had said: "...it appears the actor gained access to their production database and potentially affects all accounts and related information at Paytm Mall".

Cyble said based on information available to it, the hack happened "due to an insider at Paytm Mall" and noted that the claims, however, are unverified.

"Our sources also forwarded us the messages where the perpetrator also claimed they are receiving the ransom payment from the Paytm Mall as well. Leaking data when failing to meet hackers demands is a known technique deployed by various cybercrime groups, including ransomware operators. At this stage, we are unaware that the ransom was paid," Cyble said.

The perpetrator had reportedly demanded 10 ETH (Ethereum) equivalent to USD 4,000.

Cyble said it has reached out to Paytm Mall for any comments and is awaiting to hear back.

One subscription. Two world-class reads.

Already subscribed? Log in

Subscribe to read the full story →
*Subscribe to Business Standard digital and get complimentary access to The New York Times

Smart Quarterly

₹900

3 Months

₹300/Month

SAVE 25%

Smart Essential

₹2,700

1 Year

₹225/Month

SAVE 46%
*Complimentary New York Times access for the 2nd year will be given after 12 months

Super Saver

₹3,900

2 Years

₹162/Month

Subscribe

Renews automatically, cancel anytime

Here’s what’s included in our digital subscription plans

Exclusive premium stories online

  • Over 30 premium stories daily, handpicked by our editors

Complimentary Access to The New York Times

  • News, Games, Cooking, Audio, Wirecutter & The Athletic

Business Standard Epaper

  • Digital replica of our daily newspaper — with options to read, save, and share

Curated Newsletters

  • Insights on markets, finance, politics, tech, and more delivered to your inbox

Market Analysis & Investment Insights

  • In-depth market analysis & insights with access to The Smart Investor

Archives

  • Repository of articles and publications dating back to 1997

Ad-free Reading

  • Uninterrupted reading experience with no advertisements

Seamless Access Across All Devices

  • Access Business Standard across devices — mobile, tablet, or PC, via web or app

Topics :Paytm mallData breach

Next Story