Over 43 million investors’ data exposed in CVL security breach: Report

By Nikita Chaurasia  | Date: 2021-11-08

Over 43 million investors’ data exposed in CVL security breach: Report

CDSL Ventures Ltd. (CVL), a subsidiary of India’s leading Demat services provider Central Depository Services Limited (CDSL), greatly suffered from a vulnerability in its systems that exposed personal and financial information of about 43 million Indian investors twice in 10 days, as per Cyber9X.

Cybersecurity startup CyberX9 reported the vulnerability to CDSL on 19th October, which the securities depository took 7 days to fix.

According to CyberX9's blog, the various data types exposed include investor name, email address, income range, phone number, PAN, father's name, date of birth, and other personal information.

For the uninitiated, CDSL is a government-registered share depository responsible for managing investor accounts on the National Stock Exchange (NSE), Bombay Stock Exchange (BSE), and other stock exchanges. Whereas, CVL is a KYC (know your customer) registration agency. Both the entities are SEBI (Securities and Exchange Board of India) registered.

Himanshu Pathak, Founder and MD of CyberX9, described the exposed data in the CDSL vulnerability as a virtual gold mine for scammers, phishers, and malicious actors aiming to spread misinformation to manipulate Indian share markets.

Pathak also mentioned that two government entities NCIIPC (National Critical Information Infrastructure Protection Centre) and CERT-In (Indian Computer Emergency Response Team), accepted their vulnerability report for CDSL.

The cybersecurity researchers at CyberX9 stated that they verified the fix before publication, and it was no longer exploitable. On October 29th, their research team discovered an easy and full bypass for the initial fix that CDSL implemented to address the previously reported vulnerability in just a few minutes.

The Chandigarh-based security firm mentioned the vulnerability was not highly complex the second time their team discovered it. They believe that the attackers have already stolen the data, and the government must conduct an impartial security audit of CDSL.

Source Credit-

https://www.moneycontrol.com/news/technology/data-breach-at-cdsls-kyc-arm-exposed-4-39-crore-investors-data-twice-within-10-days-cyberx9-7687271.html

About Author

Nikita Chaurasia     aeresearch.net

Nikita Chaurasia

An accomplished professional in the field of content development, playing with words comes naturally to Nikita Chaurasia. After completing her post-graduate MBA degree in Advertising and PR, Nikita worked across numerous content-driven verticals, undertaking diverse r...

Read More >>

More News By Nikita Chaurasia

Tata Tele Business Services to offer Microsoft Azure to Indian SMBs

Tata Tele Business Services to offer Microsoft Azure to Indian SMBs

By Nikita Chaurasia

Telecommunications service provider, TTBS (Tata Tele Business Services) has reportedly announced that it would help Indian SMBs (small and medium businesses) migrate their workloads to the cloud by providing Microsoft Azure (cloud computing services)...

Tatas in plans to acquire Bisleri in a deal worth USD 856 million

Tatas in plans to acquire Bisleri in a deal worth USD 856 million

By Nikita Chaurasia

India's fast-moving consumer goods company, Tata Consumer Products Ltd is reportedly all set to acquire drink company, Bisleri International in a deal worth USD 856 million (₹7000 crores), reported the packaged water makers chairman, Ramesh...

Ukio raises $28M to offer comfort to working professionals across Europe

Ukio raises $28M to offer comfort to working professionals across Europe

By Nikita Chaurasia

Ukio, an apartment rental agency in Barcelona, Spain, has reportedly raised $28 million (€27 million) in a Series A round of funding. Apparently, the cash injection consists of over $17.5 million (€17 million) in equity and more than $10...

Amazon’s AWS unveils 2nd infrastructure region in Hyderabad, India

Amazon’s AWS unveils 2nd infrastructure region in Hyderabad, India

By Nikita Chaurasia

IT service management company, Amazon Web Services, Inc. (AWS), has recently announced the unveiling of another leading AWS infrastructure region in India, the AWS Asia Pacific (Hyderabad) Region. Starting this week, the startups, developers, ente...

Beijing reports increase in COVID-19 cases after first death in six months

Beijing reports increase in COVID-19 cases after first death in six months

By Nikita Chaurasia

World's most populous country, China has recently reported the fatalities of three people in Beijing as the first fatalities from coronavirus in the last six months, with the rise in recorded new cases despite following the strictest zero-COVID p...