Moneycontrol PRO
Loans
Loans
HomeNewsBusinessForensic audit into the data leak did not find unauthorised access, MobiKwik DRHP

Forensic audit into the data leak did not find unauthorised access, MobiKwik DRHP

The forensic audit expert however states certain limitations to the processes undertaken, including virtual walk-through of our systems, not analysing employee devices and that the review was based on logs made available by us and certain non-mandatory logs were not available for the audit, DHRP said.

July 12, 2021 / 20:16 IST

Forensic audit following MobiKwik’s data breach in March 2021 has revealed that there has been no unauthorized access, however, the company’s process has limitations, according to the draft red herring prospectus (DRHP) filed by MobiKwik on July 12.

Data breach

In March 2021, security researchers flagged that KYC data of over 3.5 million Indians had been compromised and claimed that it was the largest data leak in history.  The massive breach reportedly included KYC details of 3.5 million people and phone numbers, email, hashed passwords, addresses, bank accounts and card details of close to 10 crore users. This data was available for sale on the dark web for anyone who could pay 1.5 bitcoins, which is equal to $88434 (Rs 62,63,110).

While the company denied these claims, it launched a forensic audit over the data leak.

Forensic audit

In the DRHP, the company said, “…in March 2021, certain media reports alleged an unauthorised breach of our data security systems and gaining wrongful access to personal and financial data of our users. Following such media reports, we engaged an independent digital forensic audit expert to conduct an audit relating to these allegations.”

The forensic audit expert, the report said, analysed the logs/ data provided to them, and revealed that there was no unauthorised access from outside the company’s infrastructure or internally to the database server wherein customer data is stored, during the review period.

Read: Mobikwik data hack: Here’s how to check if your data is safe

“The report however states certain limitations to the processes undertaken, including virtual walk-through of our systems, not analysing employee devices and that the review was based on logs made available by us and certain non-mandatory logs were not available for the audit,” the report said

Apart from the incident in March 2021, over a decade ago in 2010, a hacker had gained unauthorized access to our operating systems that had resulted in certain disruption in our operations, the company said.

“Any such actual or perceived breach of our security could interrupt our operations; result in our systems or services being unavailable; result in improper disclosure of or access to data resulting in legal or financial exposure and loss of user confidence and reputation; and adversely affect our business and results of operations.

Similarly, certain vulnerabilities or breaches of network or data security at our merchants, partners or users could have similar effects and could mistakenly be attributed to us, which could also adversely affect our business, prospects, financial condition and results of operations,” the company said.

Swathi Moorthy
first published: Jul 12, 2021 08:14 pm

Discover the latest Business News, Sensex, and Nifty updates. Obtain Personal Finance insights, tax queries, and expert opinions on Moneycontrol or download the Moneycontrol App to stay updated!

Subscribe to Tech Newsletters

  • On Saturdays

    Find the best of Al News in one place, specially curated for you every weekend.

  • Daily-Weekdays

    Stay on top of the latest tech trends and biggest startup news.

Advisory Alert: It has come to our attention that certain individuals are representing themselves as affiliates of Moneycontrol and soliciting funds on the false promise of assured returns on their investments. We wish to reiterate that Moneycontrol does not solicit funds from investors and neither does it promise any assured returns. In case you are approached by anyone making such claims, please write to us at grievanceofficer@nw18.com or call on 02268882347