• About us
  • Privacy Policy
  • Contact us
Friday, July 1, 2022
  • Login
Handshake 4u
Advertisement
  • Home
  • Politics
  • Agrotech
  • Business
  • E-paper
  • Economy
  • Education
  • Entertainment
  • States
    • Andhra Pradesh
    • Arunachal Pradesh
    • Bihar
    • Assam
    • Chhattisgarh
    • Goa
    • Gujarat
    • Haryana
    • Himachal Pradesh
    • Jharkhand
    • Karnataka
    • Kerala
    • Madhya Pradesh
    • Maharashtra
    • Manipur
    • Odisha
    • Nagaland
    • Meghalaya
    • Uttar Pradesh
    • Mizoram
    • Punjab
    • Uttarakhand
    • Rajasthan
    • Sikkim
    • Tamil Nadu
    • Telangana
    • Tripura
    • West Bengal
  • Health
  • Other
    • Kitchen
    • Lifestyle
    • Market
    • Opinion
    • Tech
    • Travel
    • World
No Result
View All Result
  • Home
  • Politics
  • Agrotech
  • Business
  • E-paper
  • Economy
  • Education
  • Entertainment
  • States
    • Andhra Pradesh
    • Arunachal Pradesh
    • Bihar
    • Assam
    • Chhattisgarh
    • Goa
    • Gujarat
    • Haryana
    • Himachal Pradesh
    • Jharkhand
    • Karnataka
    • Kerala
    • Madhya Pradesh
    • Maharashtra
    • Manipur
    • Odisha
    • Nagaland
    • Meghalaya
    • Uttar Pradesh
    • Mizoram
    • Punjab
    • Uttarakhand
    • Rajasthan
    • Sikkim
    • Tamil Nadu
    • Telangana
    • Tripura
    • West Bengal
  • Health
  • Other
    • Kitchen
    • Lifestyle
    • Market
    • Opinion
    • Tech
    • Travel
    • World
No Result
View All Result
Handshake 4u
No Result
View All Result
Home Uncategorized

CDSL’s KYC arm data breach exposed 4.39 crore investors’ data twice: Report | Companies News

Handshake 4u by Handshake 4u
November 7, 2021
in Uncategorized
0

New Delhi: A vulnerability at a CDSL subsidiary, CDSL Ventures Limited (CVL), has exposed personal and financial data of over 4 crore Indian investors twice in a period of 10 days, according to cyber security consultancy startup CyberX9.

The Central Depository Services (India) Limited (CDSL) is a SEBI registered depository and CDSL Ventures Ltd is a KYC registering agency separately registered with the Securities and Exchange Board of India (SEBI).

CDSL said that CVL has taken immediate action and the vulnerability has been mitigated now.

According to CyberX9, it reported the vulnerability on October 19, to CDSL and the securities depository took around 7 days to fix it which could have been resolved immediately.

“We verified the fix before publication and it was no longer exploitable. Later, on October 29th, our research team got to work again and within a couple of minutes they found an easy and complete bypass for the fix that CDSL implemented to patch the earlier reported vulnerability.

“CERT-In and NCIIPC also accepted our vulnerability report for CDSL,” CyberX9 Founder and Managing Director Himanshu Pathak told PTI.

The exposed data includes investors name, phone number, email address, PAN, income range, father’s name, date of birth etc, CyberX9 said in its blog.

When contacted CDSL said that there has been no security issue or data vulnerability at CDSL.

“CVL had received a vulnerability alert on the website of CVL which has since been mitigated. We would like to state that CVL took immediate actions to mitigate the vulnerability and have worked proactively to further address any other potential security issues,” CDSL said.

Both the entities CDSL and CVL, as separate regulated entities with SEBI, have a clear arm’s length relationship, CDSL said.
CyberX9 said that the vulnerability was not highly complex the second time its team discovered it.

“We strongly suspect that the data might have already been stolen by malicious attackers. There is a need for a fair security audit of CDSL by the government,” CyberX9 blog said.

The Chandigarh-based cyber security startup said that the information exposed by CDSL could be a virtual gold mine for phishers and scammers involved in the so called business of e-mail compromise which often impersonate brokers, banks, and businesses in a bid to trick individuals and companies into transferring funds to fraudsters.

“Armed with such access to CDSL KYC data, phishers and scammers would have an endless supply of compelling scamming templates for calls and emails to use. A database like this would also give fraudsters a constant feed of new investors getting KYC to target them,” CyberX9 said. Also Read: Windows 7, 8, 8.1 users, Alert! Microsoft will stop offering THIS service from early 2022

The sensitive personal and financial data exposed to massive numbers of people can lead to things like financial fraud, identity theft, and exposing people to things like extortion, targeted attacks against people, etc. Also Read: Andhra Pradesh government rules out VAT cut on petrol, diesel, clears stance with newspaper ad



Source link

Previous Post

It’s a bitter pill to swallow: Mark Boucher on South Africa’s exit from T20 World Cup

Next Post

China intrudes Taiwan again, 20 Chinese warplanes enter Taipei’s ADIZ | World News

Handshake 4u

Handshake 4u

Next Post

China intrudes Taiwan again, 20 Chinese warplanes enter Taipei's ADIZ | World News

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Live Cricket Score

Corona Live Data

Recent News

सरस्वती कुंड और बिना पूंछ वाला चूहा।

November 26, 2021

शाम और ताप्ती तट..

November 17, 2021

Trump allies Michael Flynn, Jason Miller, John Eastman subpoenaed in Jan. 6 House probe

November 16, 2021

Thanks For Watching Game Informer, MinnMax, and Easy Allies’ Extra Life 2021 Charity Stream!

November 16, 2021

Today’s Weather

INDIA WEATHER

Rashifal

Handshake 4u

”I believe next generation will see another group of business tycoon , the era of Ambani will roll out from the market very soon in coming two -to-three years” – Amit Samrat.

Browse by Category

  • Andhra Pradesh
  • Business
  • Cinema
  • Culture
  • Economy
  • Education
  • Entertainment
  • Health
  • Kitchen
  • Lifestyle
  • Market
  • Odisha
  • Opinion
  • Politics
  • Punjab
  • Tech
  • Travel
  • Uncategorized
  • World

Recent News

सरस्वती कुंड और बिना पूंछ वाला चूहा।

November 26, 2021

शाम और ताप्ती तट..

November 17, 2021
  • About us
  • Privacy Policy
  • Contact us

© 2020 Handshake 4u | Designed byTraffic Tail.

No Result
View All Result
  • Home
  • Politics
  • Agrotech
  • Business
  • E-paper
  • Economy
  • Education
  • Entertainment
  • States
    • Andhra Pradesh
    • Arunachal Pradesh
    • Bihar
    • Assam
    • Chhattisgarh
    • Goa
    • Gujarat
    • Haryana
    • Himachal Pradesh
    • Jharkhand
    • Karnataka
    • Kerala
    • Madhya Pradesh
    • Maharashtra
    • Manipur
    • Odisha
    • Nagaland
    • Meghalaya
    • Uttar Pradesh
    • Mizoram
    • Punjab
    • Uttarakhand
    • Rajasthan
    • Sikkim
    • Tamil Nadu
    • Telangana
    • Tripura
    • West Bengal
  • Health
  • Other
    • Kitchen
    • Lifestyle
    • Market
    • Opinion
    • Tech
    • Travel
    • World

© 2020 Handshake 4u | Designed byTraffic Tail.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

WhatsApp us