ICICI bank closes loophole after NDTV Gadgets report

Advertisement
By Gopal Sathe | Updated: 21 April 2014 09:51 IST
Story updated to reflect latest events.

After NDTV Gadgets reported today on a loophole that allowed access to ICICI bank account statements on the internet, the bank appears to have fixed the problem.

ICICI seems to have changed how the e-statements are generated under net-banking. Directly visiting a URL that NDTV Gadgets found vulnerable, now gives a "cannot find server" message. Earlier, we were able to access monthly statements of other customers using very basic information about their accounts.

A spokesperson of ICICI bank, India's second-largest bank with subsidiaries around the world, said in a statement on Friday evening, "ICICI Bank would like to clarify that it has thoroughly checked its website and there is no vulnerability. The bank has robust systems and processes to ensure the highest standards of privacy and confidentiality of customers' data. We will investigate the said report and take appropriate actions if required."

An independent researcher, Ayush Ghosh, contacted NDTV Gadgets with information about the flaw in ICICI Bank's security protocols which allowed account statements to be accessed without logging into net banking. Journalists at NDTV Gadgets independently verified that this could be done. The method did not work for one customer, but three account statements could be accessed.

When NDTV Gadgets contacted ICICI Bank's Sujit Ganguli, Sr. General Manager, Head-Corporate Communications and Brand this morning, he said he was not aware of this vulnerability. A bank representative later told NDTV Gadgets that ICICI was working urgently to correct the problem.

While we are not revealing the exact methodology for obvious reasons, our readers should know that the method of the hack was exceedingly simple. It needed just a bit of copy-pasting and information that people don't usually think twice before sharing. You did not need to be logged in to net-banking to repeatedly exploit the loophole and you did not need to have any coding knowledge, or any sort of technical know-how.

Ghosh, who works at BookMyShow in Bangalore, contacted NDTV Gadgets with the information, which he says he noticed when operating his own account. Before contacting NDTV Gadgets, Ghosh said he tried to warn ICICI by emailing them on the contact IDs provided on the bank's website. He said he got no response.
 
It is worth noting that no one could access your account itself and so could not have carried out malicious transactions, or take any action other than seeing your account statement.

However, a person could -  till the vulnerable URL began throwing up an error - access your monthly account statement, which includes all financial transactions, along with your name and address. This is of serious concern as with access to a person's address and information like the "last three transactions" anyone can possibly call the bank and misrepresent themselves as the account holder. Alternatively, someone could call ICICI customers and pretend to be from the bank and "authenticate" themselves using the information available on these statements.
 
New Delhi-based cyber-security consultant Dominic K. spoke to NDTV Gadgets and discussed the multiple layers of security that banks have in place, which include multi-factor authentication, encryption, secure connectivity - SSL and HTTPS and identity management systems. He added, "We have not heard of any serious attacks that were successful. These are industry practices that meet global standards."
 
In light of the discovery of this flaw, it is advisable that  bank customers ensure that they use strong passwords and enable multi-factor authentication wherever possible. It is also advisable not to share passwords or even more basic details like bank account number, customer id or personal details as listed with the bank.

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Further reading: ICICI Bank, Internet
Advertisement

Related Stories

Popular Mobile Brands
  1. Amazon Great Indian Festival Sale: Deals on Smartphones, Laptops Teased
  2. Cannibal Solar Storm May Trigger Aurora in the Sky Soon
  1. BCCI Says Crypto, Real Money Gaming Platforms Can’t Bid for Team India’s Title Sponsorship
  2. Scientists Discover Hidden Mantle Layer Beneath the Himalayas Challenging Century-Old Theory
  3. Astronomers Propose Rectangular Telescope to Hunt Earth-Like Planets
  4. Microsoft Testing Native Clipboard Sync Feature to Share Text Between Windows PCs, Android Devices
  5. Su From So OTT Release: When and Where to Watch This Kannada-Language Horror-Comedy Online
  6. Sennheiser Momentum 4 Wireless 80th Anniversary Edition Launched in India With Up to 60 Hour Battery Life
  7. Call of Duty Film Adaption Said to Be a 'Priority' at Paramount, Negotiations on to Acquire Rights
  8. Cannibal Solar Storm May Trigger Auroras as Powerful Geomagnetic Storm to Hit Earth Soon
  9. Apple's iPhone 8 Plus Listed as Vintage Product Ahead of iPhone 17 Launch, 11-Inch MacBook Air Now Obsolete
  10. Hidden Reason Behind Portugal’s Deadly Earthquakes Finally Explained
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.