ADVERTISEMENT

Timely Cybernews intervention helps protect PayDo customers’ financial data

In an ongoing race, cybercriminals and security researchers relentlessly scan the web for vulnerabilities, each driven by different motivations. Cybernews was the first to discover an unprotected instance containing financial customer data, and our timely intervention helped protect customers of PayDo, a payment processor. Here are the lessons learned.

PayDo

Image by Cybernews.

Ernestas Naprys
Ernestas Naprys Senior Journalist
October 30, 2024 Updated: November 2, 2024 5 min read
Konstancija Gasaityte Linas Kmieliauskas Ernestas Naprys Stefanie
Don’t miss our latest stories on Google News
Add us as your Preferred Source on Google.

What happened?

What data was at risk?

  • Personal data related to over 20 million transactions, such as names, email addresses, and IP addresses.
  • Partial payment information for over two million transactions, including purchased items, partial payment information such as credit card bin numbers, last four digits, and cardholder name.
  • Over 58 million KYC process log entries, including customer names, addresses, dates of birth, bank account numbers, ID numbers, document numbers, and driver's license numbers. Scans and photos of documents were secured with authentication.
checkout-order

What did the company do to protect customers?

  • The DevOps team conducted a thorough analysis of event logs and AWS monitoring (specifically CloudWatch, CloudTrail, and VPC Flow Logs), which allows for the detection of any activities, such as large volumes of downloads. After this analysis, no anomalies were found, indicating that no data downloads occurred.
  • An external cybersecurity provider conducted an independent analysis of data breach tracking. According to their analysis, no signs of data leakage have been detected as of the 23rd of October, 2024. “This confirms that an independent expert evaluation also found no security issues in the system,” PayDo said.
  • Additional verification through third-party services, such as “Have I Been Pwned” and others, revealed no evidence that any data had been compromised or publicly exposed. The company did not receive any contacts from any malicious actors, which is typical when they obtain sensitive data.
  • Upgrading of the Security Operations Center (SOC).
  • Rollout of predictive MDR (Managed Detection and Response) System
  • Introduction of the Bug Bounty Program in 2025.
  • Automation of data breach detection and system availability monitoring.
  • Improvement of the Change Management and Quality Assurance processes.
  • Maintaining a dedicated communication line for bugs and data leak reports.

How dangerous was a potential impact?

ADVERTISEMENT

Lesson 1: keep communication channels open

Lesson 2: protect and sanitize instances

Lesson 3: transparency and effective mitigation are key

Lesson 4: predict human errors

Disclosure timeline

  • August 27th, 2024: Leak discovered.
  • August 28th, 2024: Initial disclosure email sent and multiple follow-up emails.
  • September 18th, 2024: Disclosure email sent to alternative email address.
  • September 20th, 2024: Instances closed to the public.
ADVERTISEMENT