Connect with us

Hi, what are you looking for?

Tech & Science

Thousands of financial records exposed without password control (Includes interview)

Investors are pumping millions of dollars into encryption as unease about data security drives a rising need for ways to keep unwanted eyes away from personal and corporate information - AFP
Investors are pumping millions of dollars into encryption as unease about data security drives a rising need for ways to keep unwanted eyes away from personal and corporate information - AFP

Citygate Global, a Nigerian Microfinance bank operates a banking application Monéé. It has been discovered by a security researcher that this data has been left exposed from its inception. From the issuing of the warning, it took ten days for the matter to addressed.

An exposed database is a collection of billions of pieces of our data, without any security preventing hackers or anyone else from stealing it and one fall-out from such incidences is that cybercriminals can leverage the breached information to impersonate the victims, make fraudulent purchases, or commit credential stuffing attacks.

In response to Monéé’s exposed database, Anurag Kahol, CTO and co-founder of Bitglass, explains to Digital Journal about the significance of the issue.

Kahol begins by outlining why the data exposed is of potential value to hackers, noting: “Personally identifiable information (PII) and financial details connected to customer accounts are valuable data that criminals can leverage to commit financial fraud, engage in identity theft, and make money on dark web marketplaces.”

This form of attack is all too common says Kahol: “This is not the first time and certainly won’t be the last time that an organization unknowingly leaves a database exposed without password protection, demonstrating how most lack full visibility and control over their data. Consequently, it’s critical that enterprises strengthen their security postures to ensure the privacy of customer and corporate data.”

In terms of what can be considered to prevent such incidences in the future, Kahol recommends: “To prevent data leakage, organizations can begin by implementing a password, followed by equipping themselves with solutions like multi-factor authentication (MFA), data loss prevention (DLP), cloud security posture management (CSPM), and user and entity behavior analytics (UEBA). These additional safety precautions will enforce stricter security standards and keep data secure.

Avatar photo
Written By

Dr. Tim Sandle is Digital Journal's Editor-at-Large for science news. Tim specializes in science, technology, environmental, business, and health journalism. He is additionally a practising microbiologist; and an author. He is also interested in history, politics and current affairs.

You may also like:

World

Taiwan's eastern Hualien region was also the epicentre of a magnitude-7.4 quake in April 3, which caused landslides around the mountainous region - Copyright...

World

A Belgian man proved that he has auto-brewery syndrome (ABS), which causes carbohydrates in his stomach to be fermented, increasing ethanol levels in his...

Tech & Science

Middle-earth Enterprises & Friends will manage the intellectual property rights Embracer has for "The Lord of the Rings" and the "Tomb Raider" games -...

Business

Honda hopes to sell only zero-emission vehicles by 2040, with a goal of going carbon-neutral in its own operations by 2050 - Copyright AFP...