Categories: Technology

Tens of thousands of Swiss credit card statements are accessible online

Between June 2021 and November 2022, monthly statements of tens of thousands of business customers were accessible over the internet due to a security breach. According to Viseca, the damage is minimal.

Tens of thousands of Swiss credit card statements were openly accessible on the Internet for a long time, the online magazine “Republik” revealed Monday.

Swiss IT security company Pentagrid accidentally stumbled upon a corresponding server vulnerability at credit card company Viseca, according to research. This vulnerability made it possible to access the foreign data simply by changing an internet address (URL).

“Every internet user could access the data ‘from the outside’ thanks to knowledge of the URL and did not need any technical knowledge or a login.”

Potentially Affected: Tens of thousands of small and medium-sized businesses (SMEs) who have a Mastercard or Visa credit card with Viseca and bill through their bank.

The Republic writes:

“The information found was highly confidential. The invoices stated which companies bought what, when and where, or in which cloud they stored their data. If someone had downloaded the data from the internet en masse, some of the companies’ business relationships could be completely reconstructed.”

Owned by the banks

Viseca is owned by the largest Swiss cantonal and retail banks. This includes all cantonal banks, the Raiffeisen Group, Entris Banking, Migros Bank, Bank Cler, regional banks, as well as private and commercial banks.

At Watson’s request, Viseca spokesperson Nicolas Kucera confirmed that a corresponding IT vulnerability had existed for 17 months. However, “no indications of improper access” were found – neither in the server logs nor through Darknet monitoring.

The vulnerability was closed within a week in November 2022 (after being reported by Pentagrid).

The conclusion of the “Republic”:

“Viseca got off with a black eye. On the one hand, because apparently no abuse has been made of the vulnerability. On the other hand, because no body feels responsible for the case and there are therefore no threats of sanctions.”

What is likely to annoy some customers: most only find out about the security incident through the reports: Viseca and the banks had refrained from informing all potentially affected themselves.

Sources

  • republic.ch: Tens of thousands of Swiss credit card statements freely available on the Internet
  • pentagrid.nl: Credit card statement disclosure of vulnerability in Viseca’s eXpense portal

(dsc)

Source: Watson

Share
Published by
Ella

Recent Posts

Terror suspect Chechen ‘hanged himself’ in Russian custody Egyptian President al-Sisi has been sworn in for a third term

On the same day of the terrorist attack on the Krokus City Hall in Moscow,…

1 year ago

Locals demand tourist tax for Tenerife: “Like a cancer consuming the island”

class="sc-cffd1e67-0 iQNQmc">1/4Residents of Tenerife have had enough of noisy and dirty tourists.It's too loud, the…

1 year ago

Agreement reached: this is how much Tuchel will receive for his departure from Bayern

class="sc-cffd1e67-0 iQNQmc">1/7Packing his things in Munich in the summer: Thomas Tuchel.After just over a year,…

1 year ago

Worst earthquake in 25 years in Taiwan +++ Number of deaths increased Is Russia running out of tanks? Now ‘Chinese coffins’ are used

At least seven people have been killed and 57 injured in severe earthquakes in the…

1 year ago

Now the moon should also have its own time (and its own clocks). These 11 photos and videos show just how intense the Taiwan earthquake was

The American space agency NASA would establish a uniform lunar time on behalf of the…

1 year ago

This is how the Swiss experienced the earthquake in Taiwan: “I saw a crack in the wall”

class="sc-cffd1e67-0 iQNQmc">1/8Bode Obwegeser was surprised by the earthquake while he was sleeping. “It was a…

1 year ago