ICICI bank closes loophole after NDTV Gadgets report

Advertisement
By Gopal Sathe | Updated: 21 April 2014 09:51 IST
Story updated to reflect latest events.

After NDTV Gadgets reported today on a loophole that allowed access to ICICI bank account statements on the internet, the bank appears to have fixed the problem.

ICICI seems to have changed how the e-statements are generated under net-banking. Directly visiting a URL that NDTV Gadgets found vulnerable, now gives a "cannot find server" message. Earlier, we were able to access monthly statements of other customers using very basic information about their accounts.

A spokesperson of ICICI bank, India's second-largest bank with subsidiaries around the world, said in a statement on Friday evening, "ICICI Bank would like to clarify that it has thoroughly checked its website and there is no vulnerability. The bank has robust systems and processes to ensure the highest standards of privacy and confidentiality of customers' data. We will investigate the said report and take appropriate actions if required."

An independent researcher, Ayush Ghosh, contacted NDTV Gadgets with information about the flaw in ICICI Bank's security protocols which allowed account statements to be accessed without logging into net banking. Journalists at NDTV Gadgets independently verified that this could be done. The method did not work for one customer, but three account statements could be accessed.

When NDTV Gadgets contacted ICICI Bank's Sujit Ganguli, Sr. General Manager, Head-Corporate Communications and Brand this morning, he said he was not aware of this vulnerability. A bank representative later told NDTV Gadgets that ICICI was working urgently to correct the problem.

While we are not revealing the exact methodology for obvious reasons, our readers should know that the method of the hack was exceedingly simple. It needed just a bit of copy-pasting and information that people don't usually think twice before sharing. You did not need to be logged in to net-banking to repeatedly exploit the loophole and you did not need to have any coding knowledge, or any sort of technical know-how.

Ghosh, who works at BookMyShow in Bangalore, contacted NDTV Gadgets with the information, which he says he noticed when operating his own account. Before contacting NDTV Gadgets, Ghosh said he tried to warn ICICI by emailing them on the contact IDs provided on the bank's website. He said he got no response.
 
It is worth noting that no one could access your account itself and so could not have carried out malicious transactions, or take any action other than seeing your account statement.

However, a person could -  till the vulnerable URL began throwing up an error - access your monthly account statement, which includes all financial transactions, along with your name and address. This is of serious concern as with access to a person's address and information like the "last three transactions" anyone can possibly call the bank and misrepresent themselves as the account holder. Alternatively, someone could call ICICI customers and pretend to be from the bank and "authenticate" themselves using the information available on these statements.
 
New Delhi-based cyber-security consultant Dominic K. spoke to NDTV Gadgets and discussed the multiple layers of security that banks have in place, which include multi-factor authentication, encryption, secure connectivity - SSL and HTTPS and identity management systems. He added, "We have not heard of any serious attacks that were successful. These are industry practices that meet global standards."
 
In light of the discovery of this flaw, it is advisable that  bank customers ensure that they use strong passwords and enable multi-factor authentication wherever possible. It is also advisable not to share passwords or even more basic details like bank account number, customer id or personal details as listed with the bank.

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: ICICI Bank, Internet
Advertisement

Related Stories

Popular Mobile Brands
  1. Bitcoin Drops Below $67,000 as ETF Outflows, Institutional Selling Intensify
  2.  Xiaomi 18, 18 Pro and 18 Pro Max Specifications Leaked Ahead of Debut
  3. RTX Spark-Powered Laptops Could Cost a Lot More Than Regular AI PCs
  4. WhatsApp's Might Soon Flag Fraudulent Chats Before You Reply to Scammers
  5. Lava Bold N2 5G Launched in India With 6,000mAh Battery, 6.75-Inch Display
  6. Honor X7e With a 7,500mAh Battery Debuts Globally at This Price
  7. Motorola Edge 2026 With 6.3-Inch Display Goes Official
  8. God of War Laufey Revealed at State of Play: Everything You Need to Know
  9. Sony Bravia 7II 4K TVs With Cognitive Processor XR Debut in India
  10. Realme P4R 5G India Launch Date, Design and Key Specifications Revealed
  1. Meta Reportedly Testing ‘Series’ Feature to Organise Instagram, Facebook Reels Into Episodic Collections
  2. Xiaomi 18 Tipped to Sport 6.4-Inch Display; Pro Models Said to Feature Dual 200-Megapixel Rear Cameras
  3. Realme P4R 5G India Launch Date Revealed Along With Design and Key Specifications
  4. Marvel's Wolverine Gets Visceral Gameplay Trailer at State of Play, Pre-Orders Now Live
  5. RTX Spark Laptops Said to Cost More Than Traditional AI PCs; Base Models Could Start at $1,799
  6. Lumio Introduces 55-Inch Variants of Vision 9 (2026) and Vision 7 (2026) Smart TVs in India: Price, Features
  7. Bitcoin Drops Below $67,000 as ETF Outflows, Institutional Selling Intensify
  8. Lava Bold N2 5G Launched in India With 6,000mAh Battery, 6.75-Inch Display: Price, Specifications
  9. WhatsApp Said to Be Developing On-Device Scam Detection Feature for Android
  10. Motorola Edge 2026 Launched With 6.3-Inch Display, MediaTek Dimensity 7450 SoC: Price, Specifications
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.