Paytm Mall says no security lapses found after investigating alleged breach by hacker group ‘John Wick’

Paytm Mall says no security lapses found after investigating alleged breach

By:PTI
| Updated on: Aug 30 2020, 23:40 IST
Paytm.
Paytm. (Reuters)

The e-commerce unit of payment solutions provider Paytm, Paytm Mall, on Sunday said it has not found any security lapses yet after investigating claims of a possible hack and data breach. 

The clarification came after US-based cyber research firm Cyble had said a hacker group with the alias 'John Wick' was able to gain unrestricted access to Paytm Mall's databases. 

You may be interested in

MobilesTablets Laptops
7% OFF
Apple iPhone 15 Pro Max
  • Black Titanium
  • 8 GB RAM
  • 256 GB Storage
28% OFF
Samsung Galaxy S23 Ultra 5G
  • Green
  • 12 GB RAM
  • 256 GB Storage
Google Pixel 8 Pro
  • Obsidian
  • 12 GB RAM
  • 128 GB Storage
Apple iPhone 15 Plus
  • Black
  • 6 GB RAM
  • 128 GB Storage

"We would like to assure that all user, as well as company data, is completely safe and secure... We have been investigating the claims of a possible hack and data breach, and haven't found any security lapses yet," a Paytm Mall spokesperson said in a statement. 

Also read
Looking for a smartphone? To check mobile finder click here.

The spokesperson added that the company invests heavily in data security, and also has a Bug Bounty programme under which it rewards responsible disclosure of any security risks. 

"We extensively work with the security research community and safely resolve security anomalies," the spokesperson said. 

Cyble, in a blog, had said: "...it appears the actor gained access to their production database and potentially affects all accounts and related information at Paytm Mall". 

Cyble said based on information available to it, the hack happened "due to an insider at Paytm Mall" and noted that the claims, however, are unverified. 

"Our sources also forwarded us the messages where the perpetrator also claimed they are receiving the ransom payment from the Paytm Mall as well. Leaking data when failing to meet hackers demands is a known technique deployed by various cybercrime groups, including ransomware operators. At this stage, we are unaware that the ransom was paid," Cyble said. 

The perpetrator had reportedly demanded 10 ETH (Ethereum) equivalent to USD 4,000. Cyble said it has reached out to Paytm Mall for any comments and is awaiting to hear back.

Catch all the Latest Tech News, Mobile News, Laptop News, Gaming news, Wearables News , How To News, also keep up with us on Whatsapp channel,Twitter, Facebook, Google News, and Instagram. For our latest videos, subscribe to our YouTube channel.

First Published Date: 30 Aug, 23:37 IST
NEXT ARTICLE BEGINS

Editor’s Pick