March 31, 2021
Payment app Mobiwik came under the scanner on Monday after a security researcher claimed that the data of 3.5 million users were put up for sale on the dark web. The researcher claimed that the sensitive information of 3.5 million users that was put on the dark web for sale includes KYC details, addresses, phone numbers, Aadhar card data and other details of the users. Several users had reportedly spotted their personal details on the dark web link that is being circulated on the internet.
Update: Mobikwik CEO Bipin Preet Singh has issued a statement on the alleged data breach involving Mobikwik. He said, “Some users have reported that their data is visible on the dark web. While we are investigating this. it is entirely possible that any user could have uploaded his information on multiple platforms. Hence. it is incorrect to suggest that the data available on the dark web has been accessed from MobiKwik or any identified source.”
“When this matter was first reported last month, the company undertook a thorough investigation with the help of external security experts and did not find any evidence of a breach. The company is closely working with requisite authorities and is confident that security protocols to store sensitive data are robust and have not been breached. Considering the seriousness of the allegations. and by way of abundant caution, it will get a third party to conduct a forensic data security audit. For our users. ve reiterate that all your MobiKwik accounts and balances are completely safe. All financially sensitive data is stored in encrypted form in our databases. No misuse of your wallet balance, credit card, or debit card is possible without the one-time-password (OTP) that only comes to your mobile number. We strongly recommend that you do not try to open any dark web anonymous links as they could jeopardize your own cyber safety. We are committed to a safe and secure Digital India.
However, the company’s claims do not match with the claims made by users who have spotted their personal details on the dark web.
The data breach was first spotted by security researcher Rajshekhar Rajaharia in February. “11 Crore Indian Cardholder’s Cards Data Including personal details & KYC soft copy(PAN, Aadhar etc) allegedly leaked from a company’s Server in India. 6 TB KYC Data and 350GB compressed mysql dump,” he had said.
The screenshots of the Mobiwik breach were posted on Twitter by another security researcher who goes by the name Elliot Alderson. He called it the “largest KYC data leak in the history”.
As per a TechNadu report, the email ids, phone numbers, passwords apps installed, phone manufacturer, IP address, GPS locations, and other details of users were leaked. The report further reveals that the alleged seller has set up a dark web portal “where one can search by phone number or email ID and get the specific results out of a total of 8.2 TB of data.”
The company had denied Rajshekhar’s claims back in February but on Monday, a link from the dark web was reportedly spotted online. Users had claimed seeing their personal details on the dark web.
Several users also posted screenshots of the Mobiwik users’ data that was up for sale on the dark web. As per reports, the data was being sold for 1.5 bitcoin or about $86,000. However, Mobiwik has outrightly denied the claims made by Rajaharia.
A company spokesperson said, “Some media-crazed so-called security researchers have repeatedly attempted to present concocted files wasting precious time of our organization as well as members of the media. We thoroughly investigated and did not find any security lapses. Our user and company data is completely safe and secure.”