#Tech news

India’s ICICI Bank exposed thousands of credit cards to ‘wrong’ users


ICICI Bank, one of Indiaā€™s top private banks, exposed the sensitive data of thousands of new credit cards to customers who were not their intended recipients.

The Mumbai-based bank confirmed to TechCrunch Thursday that its digital channels ā€œerroneously mappedā€ about 17,000 credit cards issued in the past few days to ā€œwrongā€ users. The issue came to light after some customers raised concerns on social media about the bankā€™s iMobile Pay app exposing unknown customersā€™ credit card details, including their full number and card verification value (CVV).

ā€œOur customers are our utmost priority, and we are wholeheartedly dedicated to safe guarding their interests,ā€ said Kausik Datta, corporate communications head at ICICI Bank, said in a statement emailed to TechCrunch. ā€œWe regret the inconvenience caused. No instance of misuse of a card from this set hasĀ been reportedĀ to us. However, we assure that the BankĀ will appropriately compensate a customer in case of any financial loss.ā€

The spokesperson added that the number of impacted credit cards constituted about 0.1% of the bankā€™s credit card portfolio.

As reported by the finance-related forum Technofino, sensitive data such as the full card number, expiry date and CVV of unknown customersā€™ credit cards suddenly appeared for some users on the iMobile Pay app.

ā€œI have access to someone elseā€™s Amazon Pay CC due to a security glitch on the iMobile app. Although OTP restricts domestic transactions, but I can do international transactions using the details from the iMobile app,ā€ one of the users wrote on the forum.

The bank spokesperson told TechCrunch it blocked the affected cards and is issuing new cards to customers.

ICICI Bank, which has over 6,000 branches in India, is in 17 countries worldwide. The iMobile Pay app, launched in 2008, has over 28 million users.



Source link

Leave a comment

Your email address will not be published. Required fields are marked *