What Happened In the Juspay Data Leak and What Can You Do About It?

In early January 2012 Juspay, a payment processor and gateway based in India, disclosed a data leak of millions of cardholder database records. The company published a blog post on the issue on Jan 5th.

The data leak happened due to a poorly secured server used by the company and dates back to the late summer of 2020.

How did it all happen?

Back in the second half of August 2020, Juspay became aware of unauthorized access to a database it owned. The database was hosted on an Amazon Web Services server that used an old password. The password was not just old, it was a re-used one.

Data that belonged to 35 million customers, including masked card data which the company described as "primarily used for display purposes on merchant UI". Juspay stated that the data could not be used for executing or completing a transaction.

Juspay specifically stated that the leaked information did not contain full card numbers, order details, passwords or card PINs. Despite that fact, Juspay detailed the leak to have contained plain-text email IDs and phone numbers.

Juspay actually also accused some media outlets, calling their coverage of the leak "sensationalizing" the event. While it's obviously not be the most dramatic or impactful data breach in the country, given that the stolen data was put up for sale on the dark web for a meager $5,000, it also isn't something to dismiss completely.

As a response against the incident, Juspay has reset user passwords and enabled two-factor authentication across all accounts. Those measures are common in the aftermath of similar incidents.

If you are somehow part of the affected users, the best thing you can do is to reconfirm your new password after the forced switch and keep adhering to best security practices.

Never reuse passwords across devices or services, never share passwords even with close friends and relatives, and try to use passwords that are complex enough that they can withstand brute-forcing.

January 27, 2021
Loading...

Cyclonis Backup Details & Terms

The Free Basic Cyclonis Backup plan gives you 2 GB of cloud storage space with full functionality! No credit card required. Need more storage space? Purchase a larger Cyclonis Backup plan today! To learn more about our policies and pricing, see Terms of Service, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.

Cyclonis Password Manager Details & Terms

FREE Trial: 30-Day One-Time Offer! No credit card required for Free Trial. Full functionality for the length of the Free Trial. (Full functionality after Free Trial requires subscription purchase.) To learn more about our policies and pricing, see EULA, Privacy Policy, Discount Terms and Purchase Page. If you wish to uninstall the app, please visit the Uninstallation Instructions page.