About 150 thousand profiles with personal data of Russians turned out to be freely available on the Internet - as found out RBC , all these turned out to be people who applied online for a loan at Sovcombank. Among the information leaked to the network is the full name, phone number and even the address of residence.
Ashot Oganesyan, founder of the DLBI data leak analysis service, told RBC about the appearance of a file with personal data of Russians on the darknet. The file contains more than 150 thousand profiles of citizens who applied for a loan in 2019–2020.
In addition to the loan application itself, each questionnaire contained the full name, phone number, passport details, type of loan requested, address of residence, marital status, full name and contacts of relatives, place of work, position, income, date and time of the call from bank specialists, and See also customer responses.
The announcement itself does not indicate that the applications for loans belong to Sovcombank, but its name is repeatedly mentioned in the published questionnaires. In addition, the file turned out to indicate the CRM system with which the applications were collected and processed - this is the Pyrus platform. RBC clarifies that Sovcombank is the only credit institution using the platform (the partners who use the company's solutions are listed on the official Pyrus website).
A representative of Sovcombank told the publication that they understand the source of the leak of personal data. “In May 2020, an employee of an external call center was identified in the bank, illegally copying online applications received from lead generators (service for receiving applications) that he received for calling. He planned to sell the copied data on the dark web. The attacker was detained by the police and <...> in December 2020 <...> was found guilty under article 183 of part 3 of the Criminal Code of the Russian Federation (illegal receipt and disclosure of information constituting a commercial, tax or banking secret) and sentenced to 2 years probation, "- told the bank. They clarified that already during the investigation, the employee posted an advertisement for the sale of these online applications for loans through his own Telegram channel.
According to an InfoWatch study, in the first nine months of 2020, almost 80% of data breaches from Russian companies were due to internal breaches. Moreover, in Russia the share of drains due to the fault of employees is twice as high as in the world - more than 72%.
Russians whose personal data is leaked to the network are at risk of becoming a victim of fraudsters - the latter are increasingly using deceptive methods of “social engineering” to gain confidence in a person and obtain the necessary banking data from him to withdraw funds. According to the latest data from the Central Bank, in the second quarter of 2021, fraudsters were able to steal more than 3 billion rubles from the bank accounts of Russians, more than 90% of the funds were not returned.