HomeSecurityCredit card theft from HSBC

Credit card theft from HSBC

A HSBC logo is seen above the entrance to an HSBC bank branch in New York City

A cyberattack on the IT systems of HSBC in Turkey has compromised customers' card details. However, officials appear reassuring, saying that the attackers cannot use the data for illegal transactions. The incident was detected last week through internal control mechanisms. The cyberattack led to the disclosure of card data consisting of the number, expiration date and owner's name. Account numbers linked to the cards have also been compromised.

Attackers have useless financial information

The bank, despite the fact that the attackers managed to access this information, states that there is no risk of card fraud, either through making copies or through  online transactions. Printing fake cards and withdrawing money from ATMs or using them in retail stores is not possible simply because there is not enough evidence (the magnetic stripe information and PIN code are not available) to carry out this type of fraud. In the case of online purchases, which require less information from customers, the bank does not clearly state why fraudulent transactions cannot be carried out, but one of the reasons is the absence of the code (CVV) from the list of stolen data. The CVV (Card Verification Value), or CVC (Card Verification Code) is the verification code that usually consists of the last three digits of the code printed on the back of the card. Some banks issue a four-digit CVV located on the front of the card. These verification codes are required for every online purchase to prove that the buyer actually has the card with them and the data has not been stolen from a database.

Micro-purchases can be made

On the other hand, some retailers do not ask for the security code during a purchase. This is the case for micropayments, which are limited to a certain amount. Merchants support these transactions in an effort to make the entire purchase process easy for their customers. Furthermore, it has been shown that this way customers are more willing to make small purchases. Through this process, the data that cybercriminals have in their hands is sufficient to carry out a transaction. However, in the event of a malicious transaction, cardholders are entitled to compensation.

Despite the fact that the risk of fraud is non-existent in theory, HSBC employees said that the bank's customers should not associate any illegal payments as a result of the attack on their systems. At the moment, the bank has no indications of suspicious activity regarding the affected accounts, but assured that the attack does not pose any financial risk. To prevent a similar incident, the bank has already upgraded security measures. At the same time, an investigation has been launched to reveal the identity of the attackers.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS