HomeSecurityHSBC hacked, customer data leaked

HSBC hacked, customer data leaked

International financial institution HSBC reported a breach in October. The company said names, addresses, transaction history, account information and more were exposed.
HSBC
In a statement [PDF] filed with the state of California, the bank said it was aware that some online accounts were accessed by unauthorized users between October 4 and 14. The hack affected a subset of the bank's American customers (less than 1 percent of its American customer base), the company told the BBC, but no exact numbers have been released at this time.

Leaked names, addresses, dates of birth, as well as account balances, transaction histories and account numbers.

“HSBC expresses its regret for this incident and takes responsibility for protecting its customers”, the bank says.

We have warned the customers whose accounts may have been subject to unauthorized access and we offer them one year of transaction monitoring, a theft protection service.

The hack appears to have been carried out with brute force attacks. The attackers managed to discover passwords using automated methods of checking account credentials.

Bryan Becker, application security researcher at WhiteHat Security, said:

In general, banks require some form of two-factor authentication, and this stops any attack that uses credential stuffing. Thus we have the question: Why didn't HSBC use two-factor authentication, or, if it did, what was the real cause of the breach?

______________________________

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS