Tag Archive for: lakh

Gang hacks into ATM in Delhi, uses malware to siphon off Rs 5 lakh | Delhi News


NEW DELHI: An ATM in Mayur Vihar was hacked and more than Rs five lakh were stolen from it by fraudsters. Police have registered a case in this regard.
The complainant in the case told cops that an ATM near Mayur Vihar Phase-1 was affected by a malware attack. The investigators claimed that the accused used malware to infect the system and stole Rs. 5.6 lakh. “Transactions went unrecorded by the server or ATM log due to the malware that was installed into the ATM system,” the complainant told cops.
The fraudsters visited the ATM and turned it offline. Cops are suspecting that they disconnected the local area network (LAN) and then installed a malware into the machine’s system. The fraudsters carried out transactions for more than an hour. “All transactions at the switch level were declined but, at the same time, cash was withdrawn. They used some expired ATM cards to carry out the transactions,” the complainant said.
The fraudster has done multiple random transactions of Rs 10,000, however, the cash dispensed for these transactions was Rs 20,000 for each transaction. “Instead of 20 notes of Rs 500 that had to be dispensed, 40 notes got dispensed,” the complainant added.
A similar incident was reported from an ATM installed in Ghaziabad, where the accused illegally withdrew Rs 5.6 lakh. By fudging the system with malware, the accused could cause withdrawals that are not recorded by the server or ATM log, police said.

Source…

Over 40 lakh mobile users at hacking risk from compromised Shopify API keys, Telecom News, ET Telecom


New Delhi: Over 40 lakh mobile phone users’ sensitive data is at hacking risk after cyber security researchers on Friday uncovered a critical security flaw in Shopify application programming interface (API) keys/tokens.

Cyber-security company CloudSEK‘s BeVigil, a security search engine for mobile apps, uncovered the vulnerability that puts over 40 lakh mobile customers’ sensitive data at risk.

From the millions of Android apps, 21 e-commerce apps were identified to have 22 hardcoded Shopify API keys/tokens, exposing personally identifiable information (PII) to potential threats.

By hardcoding the API key, the key becomes visible to anyone who has access to the code, including attackers or unauthorised users.

If an attacker gains access to the hardcoded key, they can use it to access sensitive data or perform actions on behalf of the program, even if they are not authorised to do so, said security researchers.

“The recent discovery of hardcoded Shopify keys in numerous Android apps is just another example of the lack of proper API security in the industry. This type of vulnerability exposes the personal information of users, as well as transactional and order details, to potential attackers,” said Vishal Singh, senior security engineer at CloudSEK.

Shopify is an e-commerce platform that allows individuals and businesses to create an online store to sell their products.

Over 4.4 million websites from more than 175 countries globally use Shopify.

With the ease of creating an online store, it also allows the integration of third-party apps and plugins to add additional functionality to the store. Shopify can be used to sell physical and digital products, and it also offers a point-of-sale system for brick-and-mortar stores.

“While this situation is not a limitation of the Shopify platform, it highlights the issue of API keys/tokens being leaked by app developers. As part of responsible disclosure, CloudSEK has notified Shopify and the affected apps about the hardcoded API keys,” said the company.

The researchers found that of the total hardcoded keys, at least 18 keys allow viewing customer-sensitive data, 7 API keys allow viewing/modifying gift cards and 6 API keys allow obtaining payment…

Source…

Over 5 lakh malware infections detected in local telco users


A staggering 5,25,820 counts of malware infections have been identified amongst the users of the four telecom operators in the country, according to the Horizon Scanning Report for Bangladesh Telecom Operators prepared by the cyber threat intelligence researchers of Bangladesh e-Government CIRT (Computer Incident Response Team). These counts of malware infections have been accounted for during the first quarter of this year, i.e. from January 2022 to April 2022.

All four telecom operators in Bangladesh have a significant infection rate of numerous malware for network communications. The total malware infections amongst the users have been accounted for during the first quarter of this year, i.e. from January 2022 to April 2022 in the Horizon Scanning Report for Bangladesh Telecom Operators.

Grameenphone, having the highest subscriber base with 83.02 million users, leads the way with 294,657 total malware counts and 47 unique counts of malware infections. The virus called ‘android.hummer’ has the highest infection rate of 24.4%.

Coming in second place is Robi Axiata, with 104,578 total malware counts, having 40 unique counts of malware infections. The ‘avalanche-andromeda’ virus has a 12.85% infection rate and leads the malware chart for the second-largest telecom operator in the country.

Meanwhile, Banglalink, having the third-highest subscriber base with 37.41 million users, has a total malware count of 98,423 with 31 unique cases of software infections. The infection rate is highest for the ‘android.hummer’ virus, as it has an infection rate of 21.64%.

Teletalk, the government-based telecom operator, has a total malware count of 28,162 with 31 unique malware infections. The ‘avalanche-andromeda’ virus has the highest count having an infection rate of 11.39%.

Unsurprisingly, all the operators have the highest number of infections in Dhaka, the capital city of Bangladesh.

According to a globally accessible knowledge base of hacking techniques based on real-world observations, developing and refining the necessary analytics is vital as it can aid in detecting evidence which can confirm the presence of…

Source…

Cyber Crimes In India Witness 572% Increase In Last 3 Years! 14 Lakh Cases In 2021 Recorded By Govt


Cyber Crimes In India Witness 572% Increase In Last 3 Years! 14 Lakh Cases In 2021 Recorded By Govt – Trak.in – Indian Business of Tech, Mobile & Startups

Source…