
The data breach affecting almost 3.2 million debit cards in the India’s banking system between May and July last year was caused by malware. Hitachi Payment Services acknowledged that in a report on Thursday, after payments and information security audit firm, SISA Information Security has completed its final assessment report.
SISA’s report notes that a piece of malicious software code in the Hitachi Payment Services’ systems caused the details of these debit cards to be compromised. The malware was described as sophisticated and “had been able to work undetected and had concealed its tracks during the compromise period.”
Although the malware’s behaviour and infiltration into the network has been decoded, the team was unable to ascertain the amount of data that was compromised, as the malware securely deleted those information. SISA confirmed the malware captured both the debit card number and PIN of customers who used their cards at the affected ATMs.
According to Tech Wire Asia, the breach was first detected after a few banks raised an alarm over the fraudulent use of their customers’ cards in China and the US, while these customers were still in India. They reported that the National Payments Corporation of India (NPCI) said over 600 customers had reported losses of at least US$195,000 (Rs1.3 crore) due to the breach.
Hitachi Payment Services said that they followed procedures immediately after the breach was discovered, informing Reserve Bank of India (RBI), National Payments Corporation of India (NPCI), banks and card schemes. The company claims that “the extent of compromise was limited and we have not seen any further misuse due to the containment measures deployed by Hitachi Payment Services.”
Loney Antony, Managing Director, Hitachi Payment Services said, “Hitachi Payment Services regrets the inconvenience caused to banks and its customers due to this lapse in its security infrastructure. We assure you of our highest commitment to building a robust infrastructure in our systems and preventing such cyber frauds in future. We have further enhanced our infrastructure and will continue to undertake all mandatory and regulatory security measures as needed.”
At current time, banks have blocked payments at international locations, reduced the withdrawal limits and monitored unusual patterns. This has helped contain financial losses. Card issuing banks have also advised customers to change their PIN or replacing cards in some cases.



