Debit card data breach: SISA to submit forensic report by October 31

As many as 32.14 lakh debit cards are feared to have been 'compromised' by cyber malware attack

Image via Shutterstock
<a href="http://www.shutterstock.com/pic-221585596/stock-photo-taking-money-out-of-atm.html" target="_blank">Image</a> via Shutterstock
Press Trust of India New Delhi
Last Updated : Oct 28 2016 | 4:37 PM IST
Bengaluru-based payment security specialist firm SISA, which has been authorised by the Reserve Bank to conduct forensic audit into the recent debit card data breach, is expected to submit its report in the next 2-3 days.

SISA is expected to give its report to RBI on October 31, sources said.

"This will give us exact picture of the entire incidence. It will give us lead as to where hacking or compromise took place," the sources said.

As many as 32.14 lakh debit cards of various public and private sector banks are feared to have been 'compromised' by cyber malware attack in some ATM systems.

The Hitachi ATMs deployed by many white-label ATM players and Yes Bank were impacted by the malware while usage at other ATMs was completely secured.

Several banks, including state-owned SBI, have recalled a number of cards while many others blocked the ones suspected to have been compromised and asked their customers to change PIN (personal identification number) before use.

Fraudulent withdrawals have been reported from 19 banks so far while complaints have been received from a few banks that their customers' cards were used fraudulently abroad, mainly in China and the US, while the customers were in India.

RBI, in a statement, earlier this week had said it came to its notice on September 8 that details of certain cards issued by some banks had been possibly compromised at ATMs linked to the ATM Switch of one of the service providers.

"The issue is currently being investigated by an approved forensic auditor, under PCI-DSS framework (Payment Card Industry Data Security Standard)," it had said.

It further said the "number of cards misused, as per currently available information, is few".

As a matter of precaution, card network operators concerned were earlier advised to share the details of cards used during the period of such exposure, it said.

The Reserve Bank further said banks have been taking "necessary remedial action to avoid any potential abuse" of such cards in future by unscrupulous elements and protect the interest of their customers.
*Subscribe to Business Standard digital and get complimentary access to The New York Times

Smart Quarterly

₹900

3 Months

₹300/Month

SAVE 25%

Smart Essential

₹2,700

1 Year

₹225/Month

SAVE 46%
*Complimentary New York Times access for the 2nd year will be given after 12 months

Super Saver

₹3,900

2 Years

₹162/Month

Subscribe

Renews automatically, cancel anytime

Here’s what’s included in our digital subscription plans

Exclusive premium stories online

  • Over 30 premium stories daily, handpicked by our editors

Complimentary Access to The New York Times

  • News, Games, Cooking, Audio, Wirecutter & The Athletic

Business Standard Epaper

  • Digital replica of our daily newspaper — with options to read, save, and share

Curated Newsletters

  • Insights on markets, finance, politics, tech, and more delivered to your inbox

Market Analysis & Investment Insights

  • In-depth market analysis & insights with access to The Smart Investor

Archives

  • Repository of articles and publications dating back to 1997

Ad-free Reading

  • Uninterrupted reading experience with no advertisements

Seamless Access Across All Devices

  • Access Business Standard across devices — mobile, tablet, or PC, via web or app

More From This Section

First Published: Oct 28 2016 | 4:22 PM IST

Next Story