Separator

Paytm Mall Suffers Massive Data Breach - Ransom Demanded by Hackers

Separator
Paytm Mall Suffers Massive Data Breach - Ransom Demanded by Hackers

CEO Insights Team, 0

The e-Commerce platform Paytm Mall has suffered a massive data breach, where a cybercrime group under the alias ‘John Wick’ has been able to get unrestricted access to the entire database of the company, according to US-based cyber-risk intelligence platform Cyble Inc.

According to Cyble, ‘John Wick’ has broken into multiple Indian companies and collected ransom from various Indian organizations including OTT platform Zee5, fintech startups, Stashfin, Sumo Payroll, Stashfin, i2ifunding, through other aliases such as ‘South Korea’ and ‘HCKINDIA’.

‘John Wick’ was able to upload a backdoor or Adminer on Paytm Mall application website and was able to gain unrestricted access to their entire database. The perpetrator claimed the hack happened due to an insider at Paytm Mall. The claims, however, are unverified, but possible.

According to Cyble, its sources also forwarded them messages where the perpetrator claims to have demanded 10 Ethereum (ETH), equivalent to $4,000 and is receiving the ransom payment from the Paytm Mall.

One of the tactics used by this group is to act as a ‘grey-hat’ hacker and offer help to companies or victims to fix their bugs, said Cyble in its report. A ‘grey hat’ is a computer hacker who looks for vulnerabilities in platforms and systems, without the owner’s knowledge and asks for a fee to fix the issue.

Paytm Mall has denied this claim and said that it has undertaken measures to verify the matter, with no data breaches detected by its internal cyber security teams as of Sunday evening.

“We would like to assure that all user as well as company data is completely safe and secure. We invest heavily in our data security, as you would expect.

‘John Wick’ has broken into multiple Indian companies and collected ransom from various Indian organizations including OTT platform Zee5, fintech startups, Stashfin, Sumo Payroll, Stashfin, i2ifunding, through other aliases such as ‘South Korea’ and ‘HCKINDIA’



We have been investigating the claims of a possible hack and data breach, and haven’t found any security lapses yet. We also have a Bug Bounty program, under which we reward responsible disclosure of any security risks. We extensively work with the security research community and safely resolve security anomalies,” says a Paytm Mall spokesperson.

In July, hyperlocal task management startup Dunzo also suffered a data breach that leaked phone numbers and email addresses of its users. “The data breach took place through servers of a third party Dunzo whose works were compromised,” Mukund Jha, CTO, Dunzo. There have been several Indian platforms in the past which have faced data breaches.

Earlier in May, it was reported that data of 4.75 crore Truecaller Indian users was found to be up for sale on the dark web. The development which was denied by the Swedish mobile application platform Truecaller India, was a result from its data leak.

In January, 2019, Amazon India had admitted to a technical glitch which exposed tax reports of 400,000 sellers on its platform. It was reported that affected sellers received tax reports of other sellers, while attempting to download their own Merchant Tax Reports for December, 2018.

A recent survey by network security provider, Barracuda Networks said that around 66 percent of Indian organizations have suffered at least one data breach after shifting to the remote working model, which included 1,000 decision makers in India, Australia, New Zealand, Singapore, and Hong Kong.

In Print




Most Viewed

From 'Volume' to 'Value': India Inc's Mantra to Capture the Global Pharmaceutical Market A Fight Back from Arabian Peninsula When will The Tech Industry’s Lay-off Season End? The Story of a Broken Trust Technology Key To Global Travel Recovery What To Keep In Mind When Selecting The Right Air Compressor For Replacement? The Best Way to Recover from Ransomware Attacks How Tensions Grew Worse between Elon Musk and Donald Trump New Markets, New Brands: Tailoring Success for Different Places Empowered Leadership in a Changing Legal World Four Key Steps For Healthcare Providers To Combat Ransomware Turning Vision into Value: How I Built Purposeful Digital Ecosystems in the UK Dave Thomas: A Role Model for Aspiring Entrepreneurs, Philanthropists Digital Analytics Products: How Organizations Choose Them Kelly Ortberg: The New Boeing CEO Who is Already on the Headlines India’s Military Alacrity for Modern Threats Reshma Saujani: Reshaping Social Attitudes Around Gender and Tech India is Manifesting Leadership in Drone Technology 5 Greatest Role Models in the Manufacturing Industry Creating a Stronger Ecosystem by Fixing the Nuts & Bolts of the Economy Microsoft for India: Making India for Future Ready India's UPI Launch in France Opens Gateway to Global Fintech Power Tim Cook Nears Retirement, Who Will Take Over Apple's Throne? Soil Based Microbial Fuel Cells Could Protect the Environment from Flammable Chemicals The mantra of Academic Collaboration Echoes on this Teachers’ Day Indian semiconductor Boom Has Abundant Room for SME-preneurs Indian Healthcare Ecosystem is Hosting a Multidimensional Paradigm Shift Being a True Republic: You Got to Love this New, Powerful India Qatar World Cup 2022 Might Be Over, But Arabian Peninsula’s Sports Dream is Just Beginning Reimagining the UK–India Partnership in a Changing Global Order These Schemes Will Facilitate Women Entrepreneurs Decarbonization & Sustainable Future: Technology & What it can Do?


🍪 Do you like Cookies?

We use cookies to ensure you get the best experience. Read more…