The data of more than 420 thousand employees of Sberbank illegally got into the network - possibly due to the deliberate actions of one of the employees, writes Kommersant . Such a leak does not threaten customers, but a bank that has failed to protect even the data of its own employees is threatened with reputational losses.
Details
- A few days ago, employee data was posted anonymously in one free file on a specialized hacker forum. The text document contained over 421,000 records with the full names of employees and their logins for entering the operating system, which in most cases coincide with their email addresses. The document contained data on employees of subsidiaries and foreign branches of Sberbank and made it possible to establish in which department the employee works.
- The total size of the base exceeds the number of all employees of the bank - now it is about 300 thousand people. This may be due to the fact that the database contains data on some laid-off employees, the newspaper notes. In the file, among others, there are three e-mails of the bank's president, German Gref.
- The published information “does not pose any threat to automated systems and customers,” Sberbank assured the newspaper, without disclosing the exact cause of the leak. The most likely, according to the bank, "malicious actions" of one of the current or former employees. This address book is available to all employees of Sberbank and "does not pose a threat of disclosure of their personal data," the bank's press service emphasized. The problem was reported to Gref, who has already expressed his dissatisfaction, said one of the newspaper's interlocutors in the bank.
- According to the publication, the Central Bank is also aware of the data leak of the bank, which considers the situation "unpleasant". The Central Bank did not respond to the official request of Kommersant.
- For Sberbank, an organization with serious information protection, for example, against phishing attacks, such a leak primarily carries reputational, rather than cybernetic risks, Sergey Chernokozinsky, head of the information security department at OTP Bank, told Kommersant: “The data can be used to send mass phishing emails. , advertising, spam, but serious banks are able to cope with such problems.
- Bank customers may doubt that a bank that has failed to protect the data of its own employees ensures the security of client information well, Ilya Zharsky, partner of the Veta expert group, agrees. Such data leaks have recently been occurring regularly in many areas, they are dangerous for those whose data is publicly available, the bank itself receives only damage to its reputation, sums up Vladislav Tushkanov, a web analyst at Kaspersky Lab.
What do I get from this?
The leak should not threaten Sberbank customers - their data was not made publicly available. If we are really talking about data available to all Sberbank employees, this means that there was no intruder penetration into the bank's internal systems. Nevertheless, the leakage of such a large array raises questions about the organization of access to data in the largest bank.
Artem Gubenko