PNB Server exposed personal information of over 180 million customers
By MYBRANDBOOK
According to cyber security firm CyberX9, a vulnerability in the server of Punjab National Bank (PNB) allegedly exposed the personal and financial information of its about 180 million customers for about seven months. The vulnerability provided access to the entire digital banking system of PNB with administrative control. Meanwhile, the bank has confirmed the glitch but denied any exposure of critical data.
The bank has confirmed about the glitch but denied any exposure of critical data due to the vulnerability. PNB said "customer data/applications are not affected due to this" and "server has been shut down as a precautionary measure."
CyberX9 founder and MD Himanshu Pathak said that that vulnerability was found in an exchange server which is interconnected with other exchanges and shares all access -- including access to all email addresses which results in access to all email addresses.
"The vulnerability which we discovered was leading to the highest level of admin privilege in PNB's exchange servers. If you gain access to Domain Controller through an exchange server then the doors very easily open to make any computer accessible in the network. These computers even include those that are being used in their branches and other departments," Pathak said.
Responding to the cyber security firm’s comment, PNB said, "The server wherein the vulnerability was reported, was being used as one of the multiple Exchange Hybrid servers used to route emails from On-prem to Office 365 Cloud. There is no sensitive/critical data in this server."
Nazara and ONDC set to transform in-game monetization with ‘
Nazara Technologies has teamed up with the Open Network for Digital Comme...
Jio Platforms and NICSI to offer cloud services to government
In a collaborative initiative, the National Informatics Centre Services In...
BSNL awards ₹5,000 Cr Project to RVNL-Led Consortium
A syndicate led by Rail Vikas Nigam Limited (abbreviated as RVNL), along wi...
Pinterest tracks users without consent, alleges complaint
A recent complaint alleges that Pinterest, the popular image-sharing platf...
TAC SECURITY SOLUTIONS
DELL TECHNOLOGIES INDIA PVT. LTD.
VVDN TECHNOLOGIES
HIMACHAL FUTURISTIC COMMUNICATIONS LTD.
Icons Of India : Girish Mathrubootham
Girish Mathrubootham is the Founder of Freshworks (previously known ...
Icons Of India : Debjani Ghosh
Debjani Ghosh is the President of the National Association of Software...
Icons Of India : NANDAN NILEKANI
Nandan Nilekani is the Co-Founder and Chairman of Infosys Technologies...
NSE - National Stock Exchange
NSE is the leading stock exchange in India....
UIDAI - Unique Identification Authority of India
UIDAI and the Aadhaar system represent a significant milestone in Indi...
LIC - Life Insurance Corporation of India
LIC is the largest state-owned life insurance company in India...
Indian Tech Talent Excelling The Tech World - Rajiv Ramaswami, President & CEO, Nutanix Technologies
Rajiv Ramaswami, President and CEO of Nutanix, brings over 30 years of...
Indian Tech Talent Excelling The Tech World - Anirudh Devgan , President, Cadence Design
Anirudh Devgan, the Global President and CEO of Cadence Design Systems...
Indian Tech Talent Excelling The Tech World - JAYASHREE ULLAL, President and CEO - Arista Network
Jayshree V. Ullal is a British-American billionaire businesswoman, ser...