SBI Left Banking Data of Millions of Users Unprotected Online: Report

Advertisement
By Gaurav Shukla | Updated: 31 January 2019 10:47 IST
Highlights
  • The password-less SBI server is said to have been secured now
  • The server allegedly included two months of data from SBI Quick
  • SBI is the largest bank in India with over 42 crore customers

SBI Quick service allows users to check their account balance and more over SMS or via a missed call

State Bank of India has found itself in the middle of a data security scandal as a media report on Wednesday claimed that the India's largest bank left a server with the banking data of its consumers unprotected. The reported server is said to have been secured since then, but the existence of an alleged unprotected server raises serious questions about the security practices at the bank, which manages the money of over 42 crore customers across India.

According to a report by TechCrunch, the alleged unprotected server of the State Bank of India was housed in a Mumbai data centre and included two months of data from SBI Quick, a missed call banking service from the company. SBI Quick is claimed to offer an easy and non-connected way to its consumers to get basic information about their account with the bank. The consumers can ask for their balance, mini statement, request a cheque book, and more.

The SBI server was apparently not protected by a password, thus giving anyone, who knew where to look for, access to the banking data of millions of customers, including their mobile numbers, partial account numbers, account balance, recent transactions and more. TechCrunch says the leak was discovered by a security researcher, who wants to remain anonymous.

Advertisement

The report explains the server essentially housed the back-end system of the SBI Quick service and included millions of messages that were being sent to the consumers in response to their queries. It added that they could allegedly see the text messages being sent in real-time. The website states that it verified the authenticity of the server by asking one India-based security researcher to use the SBI Quick service and within seconds, they reportedly could see the researcher's number as well as the response sent to him on the password-less server.

Advertisement

TechCrunch says the server revealed that the bank sent over three million text messages to the consumers on Monday itself. With two months of such data, a malicious party could do a lot of damage to the unsuspecting State Bank of India consumers.

We have reached out to SBI for a statement on the matter but did not get a response at the time of publication.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Supernatural Thriller Jatadhara Now Streaming on OTT: All the Details
  2. OnePlus 15R Confirmed to Come With 32-Megapixel Selfie Camera
  1. Kepler and TESS Discoveries Help Astronomers Confirm Over 6,000 Exoplanets Orbiting Other Stars
  2. Supernatural Thriller Jatadhara Arrives on OTT: Where to Watch Sonakashi Sinha-Starrer Film Online?
  3. OnePlus 15R Confirmed to Come With 32-Megapixel Selfie Camera, 4K Video Recording Support
  4. Rocket Lab Clears Final Tests for New 'Hungry Hippo' Fairing on Neutron Rocket
  5. Apple Rolls Out iOS 26.2 Update for iPhone With Liquid Glass Customisation, Changes to Apple Music, and More
  6. Aaromaley Now Streaming on JioHotstar: Everything You Need to Know About This Tamil Romantic-Comedy
  7. Astronomers Observe Star’s Wobbling Orbit, Confirming Einstein’s Frame-Dragging
  8. Galaxy Collisions Found to Activate Supermassive Black Holes, Euclid Data Shows
  9. JWST Detects Oldest Supernova Ever Seen, Linked to GRB 250314A
  10. Chandra’s New X-Ray Mapping Exposes the Invisible Engines Powering Galaxy Clusters
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.