Cosmos Bank fraud due to malware in system: NPCI

August 15, 2018 11:46 pm | Updated August 16, 2018 08:03 am IST - Mumbai

The National Payments Corporation of India (NPCI) has said the recent incident of cyber attack in Pune-based Cosmos Cooperative Bank, that has caused an over ₹90-crore loss, is due to a malware attack on the bank’s system.

Hackers transferred over ₹90 crore out on August 11 and 13 through the malware attack on the bank's server by cloning debit cards of the bank’s customers. The transactions were carried through automated teller machines (ATMs) in 28 countries, including Canada, Hong Kong and India. Visa and Rupay debit cards were cloned. The bank registered an FIR with the Chatushringi police station and has closed all its servers and net banking facilities.

“One of our network members has confirmed a malware attack on their system,” NPCI said, while reiterating that its systems are fully secured and that this issue has occurred within the bank’s information technology environment.

Bharat Panchal, Head Risk Management, NPCI said, maximum transactions have been reported from outside India. “We wish to reiterate that our systems are fully secure and we are monitoring the situation continuously. We are there to support the bank in identifying the cause of this fraud.”

After banks failed to upgrade their software in ATMs despite repeated reminders, Reserve Bank of India has directed them to complete the process in a phased manner latest by June 2019. The banking regulator pointed out that many ATMs were still running on Windows XP and other unsupported software. According to banking industry sources, at least 30% of the 2.2 lakh ATMs across the country could still be running on old software.

Jayant Saran, Partner, Deloitte India, said continuous monitoring and surveillance was required to prevent such attacks. “Banking institutions are vulnerable to cyber attacks. Continuous monitoring, surveillance and incidence response teams deployed on standby can be beneficial in preventing large-scale attacks,” Mr. Saran said.

0 / 0
Sign in to unlock member-only benefits!
  • Access 10 free stories every month
  • Save stories to read later
  • Access to comment on every story
  • Sign-up/manage your newsletter subscriptions with a single click
  • Get notified by email for early access to discounts & offers on our products
Sign in

Comments

Comments have to be in English, and in full sentences. They cannot be abusive or personal. Please abide by our community guidelines for posting your comments.

We have migrated to a new commenting platform. If you are already a registered user of The Hindu and logged in, you may continue to engage with our articles. If you do not have an account please register and login to post comments. Users can access their older comments by logging into their accounts on Vuukle.