TechCrunch News 2024年12月03日
Indian online ID verification firm Signzy confirms security incident
index_new5.html
../../../zaker_core/zaker_tpl_static/wap/tpl_guoji1.html

 

Signzy为多家金融机构提供服务,上周遭网络攻击。该公司已确认安全事件,但未详细说明。多个相关方对此做出回应,包括CERT-In、部分客户等。Signzy称已聘请专业机构调查。

📌Signzy为全球600多家金融机构服务,包括印度四大银行

💻上周Signzy遭网络攻击,部分客户担心客户数据泄露

🔍Signzy已聘请专业机构进行安全事件调查并通知相关方

👀CERT-In知晓该事件并正与有关部门采取适当行动

Signzy, a popular vendor offering online “know your customer” ID verification and customer onboarding services to several top financial institutions, commercial banks, and fintech companies, has confirmed a security incident, TechCrunch can exclusively report.

The Bengaluru-based startup, which serves over 600 financial institutions globally — including the four largest Indian banks, was hit by a cyberattack last week, according to sources speaking with TechCrunch. On Saturday, Signzy told TechCrunch it was aware of the security incident but declined to elaborate.

India’s computer emergency response team, known as CERT-In, separately acknowledged TechCrunch that it was aware of the incident and “in process of taking appropriate action with the concerned authority.”

Founded in 2015, Signzy enables onboarding for 10 million customers and businesses monthly. The startup, which has offices in New York and Dubai — in addition to its India offices in Bengaluru, Gurugram, and Mumbai — counts several major companies among its key customers, including ICICI Bank, SBI, MSwipe, and Aditya Birla Financial Services.

TechCrunch learned about the security incident from sources, including two Signzy clients, who were concerned about the alleged customer data that briefly appeared on a cybercrime forum post, which TechCrunch has seen.

PayU, another Signzy customer, said that Signzy was hit by an “information stealer malware” and asserted that it had no exposure to the incident.

“There is no impact on PayU customers or their data due to Signzy’s information stealer malware. We have received written confirmation from the vendor that PayU and its customers’ data have not been compromised and remain secure with the best security standards in place,” PayU spokesperson Dimple Mehta told TechCrunch.

Other customers said they were unaffected. When asked by TechCrunch, ICICI Bank stated that it had no exposure to the incident.

In a statement to TechCrunch, Signzy declined to comment on whether customer data had been exfiltrated. Debdoot Majumder, a spokesperson representing Signzy, said the company had hired a “professional agency for conducting the security incident investigation.”

The startup, backed by investors including Mastercard, Vertex Ventures, Kalaari Capital, and Gaja Capital, said it had informed its clients, regulators and stakeholders about the security incident.

When asked if the firm had engaged with the Reserve Bank of India, the country’s central bank, Signzy said it had no communication. The central bank didn’t respond to a request for comment.

Fish AI Reader

Fish AI Reader

AI辅助创作,多种专业模板,深度分析,高质量内容生成。从观点提取到深度思考,FishAI为您提供全方位的创作支持。新版本引入自定义参数,让您的创作更加个性化和精准。

FishAI

FishAI

鱼阅,AI 时代的下一个智能信息助手,助你摆脱信息焦虑

联系邮箱 441953276@qq.com

相关标签

Signzy 网络攻击 安全事件 客户数据
相关文章