
At a specialized forum, the data of Alfa Bank credit card holders was put up for sale. The bank confirmed the leak, saying that it affects a small number of clients and does not pose a threat to the money in their accounts, writes RBC .
The data of Alfa Bank credit card holders and AlfaStrakhovanie clients was put up for sale. The seller, who published the corresponding announcement on one of the specialized forums, stated that he has fresh data from approximately 3.5 thousand clients of Alfa Bank and about 3 thousand clients of AlfaStrakhovanie. The ad was published on October 31, the seller registered on the same day.
The free sample contained 13 contracts of Alfa Bank clients and ten contracts of AlfaStrakhovanie clients. The contracts contain the full name, mobile phone number, passport data, registration address, the amount of the credit limit or insurance issued, the subject of insurance, as well as the date of conclusion of the contract. According to the seller, all Alfa Bank contracts that he has at his disposal were executed in October, and the database was unloaded on October 22. The contracts concluded with AlfaStrakhovanie were executed on one day - May 8, 2019.
RBC checked Alfa Bank clients. When trying to transfer money to them through a mobile application using a phone number, in 11 cases out of 13, the names, patronymics and first letters of surnames in the application coincided with those specified in the contract; the remaining two phone numbers were not linked to the bank card. We managed to reach nine clients: most of them, including those who could not be verified through the mobile application, confirmed that they had recently issued a credit card at Alfa Bank. Fraudsters have already called one of the clients and blocked the card.
The client data specified in the AlfaStrakhovanie contracts was not confirmed as a result of the verification. Some contracts do not contain a full name or telephone number, and a few more contain erroneous patronymics and the subject of insurance. It was possible to get through to only four numbers out of ten; none of the interlocutors could fully confirm the information or refused to talk.
A representative of Alfa Bank confirmed the fact of the dissemination of personal data of 15 clients, clarifying that the bank is conducting an internal investigation to identify the scale and circumstances of the incident. According to him, we are not talking about a violation of the security of the bank’s corporate information system, and the leak itself does not contain any data necessary to access accounts.
At the same time, fraudsters can use the information to, for example, call a client under the guise of a bank and find out card numbers and CVV codes. However, banks never request such information when communicating with clients. If such a call is received, then you need to call the bank back at the number indicated on the website or on the card.
A representative of AlfaStrakhovanie said that the company “is aware of the fact that advertisements have been placed on the Internet for the sale of data under insurance contracts for electronic devices.” AlfaStrakhovanie has already introduced additional security measures; it is now conducting an investigation and checking the published data.
According to experts, the data leak could have been organized by a bank employee who decided to “earn extra money.” The source of the leak could be employees of the credit department or the pre-trial debt repayment department, who have access to various databases for checking clients. Such data is of interest to fraudsters who contact potential victims on behalf of the bank in order to steal funds, or to competitors who, based on knowledge of the services used, offer more favorable conditions.
On October 23, reports appeared in the media about a database with data from Sberbank clients put up for sale online, containing information about borrowers in arrears. At the same time, the seller claimed that he could provide records of the last calls of these clients to the bank.
Sberbank stated that there was no data leak in the organization, and the founder and technical director of DeviceLock, Ashot Oganesyan, suggested that the leak could have occurred in an external call center that provides work with debtors. Subsequently, it became known about the arrest of an employee of the collection company National Collection Service (NSV), which had previously entered into a cooperation agreement with Sberbank.
At the beginning of October, it became known about the leak of credit card data of Sberbank clients. The media wrote that data sellers on the black market allegedly obtained data from 60 million credit cards, both active and closed. Sberbank subsequently stated that so many credit cards were simply not issued: there are approximately 18 million active ones, and in total the bank has issued about 40 million cards. Soon the bank issued a press release, which talked about the leak of card data of 200 clients, but later the bank admitted that the data of 5 thousand cards had been leaked. The bank also reported that customer data was stolen by a 28-year-old sector manager in one of the bank’s business units, who had access to the databases.