The story of the data leak of half a million employees of Sberbank into the network continued - along with the data of people, archived technical documents describing how the bank checks the performance of its own systems also turned out to be publicly available, writes Kommersant . This is not an intentional hack, but the careless actions of one employee, experts are sure. The bank itself emphasizes that the leaked files do not contain trade secrets and personal information.
Details
- Cybersecurity experts interviewed by the newspaper got acquainted with the archived file that got into the network and agreed that the leak was the fault of one of the employees: wanting to work at home, he sent work files to his home mail.
- “The files contained in the archive are official documents, they relate to the integration of software development and operation (DevOps) processes,” Zecurion CEO Alexei Raevsky told the publication. According to the head of the information security service of a bank from the top 30, these files are an unfinished draft of a project for a specific Sberbank system. According to Kommersant’s interlocutor close to law enforcement, the files that have become public show what systems the bank uses and how it checks their serviceability – for some criminals, they may be of value because they show certain vulnerabilities.
- The bank itself emphasized that its information systems were not hacked, and the files that got into the network do not contain banking, commercial secrets and personal data of employees and customers of the bank. "The archive contains working technical documentation, the exchange of which is possible, including with contractors, via the Internet to perform production tasks," the newspaper quotes the bank's press service.
Context
- At the end of October, Kommersant announced that the data of more than 420,000 former and current employees of Sberbank appeared in public access - records of their full names and logins for entering the operating system were posted on a specialized hacker forum in one file, which in most cases coincide with email addresses .
- The document contained data on employees of subsidiaries and foreign branches of Sberbank and made it possible to establish in which department the employee works. In the file, among others, there are three e-mails of the president of the bank, German Gref.
The leak is an important signal for Sberbank, experts say. “The ability to send restricted information to an external address may indicate a low culture of information security in a particular company, as well as the lack of high-quality protection against leaks,” Raevsky believes. Now any leak is a "time bomb", he adds: there are no guarantees that in the future it cannot be used by criminals.
Artem Gubenko