State Bank of India (SBI), one of India's largest banks, left millions of financial data related to its customers exposed, according to a report by TechCrunch.
The Mumbai-based server, which has now been secured, was storing over two months of user data, including bank balances, transaction history and more.
The report says the data was pulled from “SBI Quick” – one of the bank’s free services, which allows customers to view their account balance, transaction statements and more by sending SMS with predefined keywords.
For example, if someone wants to inquire about their balance, they can use this service by texting the word “BAL” to a specific number. In response, the server will display the total balance of the bank account associated with the number.
Because of the insecure database, the TechCrunch team was able to see messages being sent to customers via the server in real time. The data they were able to see included phone numbers, bank balances, and recent transactions.
To verify whether the database actually hosts SBI customer data – the team asked security researcher Karan Saini, who works in India, to send a message through the ‘SBI Quick’ service.
Within seconds, his phone number along with the message he received was tracked by the team.
It is unclear how long the server was unprotected without any password, but any tech-savvy person would know where to look and could access data on millions of bank account holders of the State Bank of India.
This is probably one of the biggest data breaches of Indian citizens since the Aadhaar data leak – where data of more than 1.2 billion users was exposed, in early 2018.
