Android Century
  • Home
  • Android Zone
    • Android Apps
    • Android Games
    • Apps APk Files
    • Games Apk Files
    • Apps Hack Tricks
  • Reviews
  • Fantasy Zone
    • Entertainment
    • Quotes and Status
    • Life Style
    • Home Made Tips
    • Hair Care
    • Skin Care
    • Fantasy Tips
  • Tricks
    • Free Recharge
    • Free Internet
    • shopping Cashback
    • Recharge Cashback
  • Tech
  • Mobiles
  • Gadgets
  • News
  • How To's
  • Software
Breaking
Loading...

Featured post

How to Take Great Photos With Apple's iPhone X

Recent Posts

Labels

  • Android Apk Files
  • Android Apps
  • Android Games
  • Apps Apk Files
  • Entertainment
  • Fantasy Tips
  • Gadgets
  • Hair Care
  • HomeMade Tips
  • How To's
  • News
  • Quotes
  • Quotes & Status
  • Recharge Cashback
  • Recharge Promo Codes
  • Shopping Cashback
  • Technology
  • skin care
Home / News / Bank of Maharashtra's UPI app trojan horse: vintage global fraud the use of new age toys

Bank of Maharashtra's UPI app trojan horse: vintage global fraud the use of new age toys

Latest Govt. Jobs 20:48:00 News Edit
Bank of Maharashtra's UPI app bug: Old world fraud using new age toys

A fortnight ago, in an email advisory, the National Payments Corporation of India (NPCI) - the central switch and umbrella organisation for retail payments - reiterated a simple message to all large banks.

It said that everyday a bank must match transactions on its UPI apps with data it receives from NPCI. Reconciling outflow of money with inflow is a practice that every banker learns during the first week in the job.

The communiqué, however, was a grim reminder of the price a bank may have to pay if it ignores this ancient tradition of the trade; and, it follows the bitter experience of a government-owned bank in Maharashtra which recently discovered that Rs 25 crore was quietly pilfered from multiple accounts over a few months by a gang of 50.

Just armed with smartphones and a few GBs of data, the members of this syndicate were spread over smaller towns like Aurangabad, Latur, and Nashik to execute their plan.

Fraudsters don't have to necessarily hack into a bank's system and IT network to rob it; they can still manage a neat job to pull out money with the age-old technique of spotting a chink.

Contrary to popular belief and some media reports, the fraud in the Maharashtra bank wasn't a cyber crime: the bank's system was not hacked and no virus found its way to divert funds from one account to another or make its ATMs spew out cash. What took place was amazingly simple.

Think how the bank's app works. It's based on United Payment Interface (UPI), a technology that helps to move money from one bank account to another with a few clicks on a mobile phone. When money is transferred from one account to another - say when a shopper keys in the 4-digit PIN to 'push' money from her account to a grocer's account - certain IT systems 'talk' with each other to complete the transaction.

First, the mobile app system of the shopper's bank communicates with the bank's core banking system to make sure a few basic things are in place - such as, the shopper's account is active and there's enough balance.

Once this is done, the bank's UPI system sends a message to the NPCI system (that acts as a hub-n-spoke body through which communication from one bank to another pass); the NPCI system then reaches out to the shopkeeper's UPI app which in turn signals the core banking network of the shopkeeper's bank to finally credit the money and close the transaction.

UPI also offers a 'pull' transaction that's unique to the technology. This is used when the grocer 'pulls' money from the shopper's account. Here too, banks' IT systems talk to each other in exactly the same way; the money transfer is complete only after the latter shopper approves the 'pull' request with a simple PIN.

No bank talks to the other directly, but communicate through NPCI; secondly, a transaction goes through (rather supposed to) only after a bank's core banking system okays the fund transfer initiated by the same bank's UPI app.

Virtual Money

The loophole in the Maharashtra bank was the gap between its core banking system and the UPI app system; the UPI system could not accurately interpret the message from the core banking system.

What does it mean? If someone tries to pull money out of an account that has little or no balance, the core system of the bank should normally sent out a 'decline' signal and reject the transaction.

In this case too it sent out a signal. But the bank's UPI system read the 'decline' message as 'accept'. Thus, money moved from UPI accounts of the Maharashtra bank to accounts in other banks even though there was no money in the Maharashtra bank's accounts.

The absence of adequate fund could not stop the fraudster from pulling virtual money out from multiple accounts to other banks' accounts and spend. It's like a bank clearing a string of cheques on accounts with no fund, instead of letting the instruments bounce.

How did the fraudsters go about?

The one solid information they had was the gap - or the security mismatch - between the core and UPI systems of the bank; armed with this information they opened hundreds of accounts with very little balance, and 'pulled' funds -- far more than what was there in the accounts - using the UPI handle of these accounts.

The accounts from which funds were pulled out as well as the accounts into which the money flowed into belonged to the group of swindlers. It was a fraud where money moved despite the fact that there was no money .

Perhaps, one in the gang stumbled upon the information by sheer luck. May be, he tried to pull out Rs 1,000 when only was Rs 50 lying in an account. It worked.

The rest was a bit of planning and luring others looking for easy money. Perhaps, bankers of 'Digital India' may note that fraudsters can beat new age toys with old world tools.
Share on Facebook Share on Twitter Share on Google Plus

RELATED POSTS


LG G7 with iPhone X-like notch

Oppo F7 India launch confirmed

Alcatel 1x with Android Oreo (Go ed...
Bank of Maharashtra's UPI app trojan horse: vintage global fraud the use of new age toys Bank of Maharashtra's UPI app trojan horse: vintage global fraud the use of new age toys Reviewed by Latest Govt. Jobs on 20:48:00 Rating: 5

0 comments:

Post a Comment

Newer Post Older Post Home
Subscribe to: Post Comments ( Atom )

Search This Blog

TEST BOOK FOR GOVT ENTRANCE TEST

TEST BOOK FOR GOVT ENTRANCE TEST
Find All Latest book for preparation of SSC,RAILWAYBANK PO,RBI,BANK CLERK,GATE ME,GATE CE are available here in less prices, to check out the books click here

Translate

  • Popular Post
  • Random posts
  • Category

Popular Posts

  • Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Refer & Earn Offer:  Hey Guys! Today I make an article about Teen Patti Referral ...
  • Hands-on with the home windows 10 Creators update for the Xbox One: Beam recreation streaming arrives
    The Windows 10 Creators Update is here, now—yes,  now —but not (officially) on the PC. The ...
  • Taotronics TT-BH22 Headphones Review
    We make it a addiction to now not look up pricing of a product sooner than reviewing and if ...
  • Pentagon strongly condemns North Korea missile test
    The Pentagon on Monday strongly condemned North Korea’s latest missile test, adding that the ...
  • Reliance Jio to offer sharp tariff discounts for customers signing up by March-end
    Reliance Industries' Jio unit will charge a tariff for its services from April, but will offer ...
  • Bank wallets growing faster than e-wallets
    In the  bank  versus  e-wallets  sweepstakes,  lenders  have now gained lost ground. As of ...

Random Posts

  • jabong cashback offer – Get 10% cashback when you pay with Paytm Wallet
    jabong cashback offer – Get 10% cashback when you pay with Paytm Wallet
    07.04.2016 - 0 Comments
    Jabong Paytm Offer – Now get 10% cashback on minimum transaction amount of Rs 999 when you pay via Paytm…
  • Libratone One Click Bluetooth speaker Review
    Libratone One Click Bluetooth speaker Review
    08.07.2017 - 0 Comments
    Libratone marches to a different drummer than maximum different Bluetooth speaker producers, and that’s best…
  • JOBS - Twitter may lay off about 300 before Q3 earnings announcement: Report
    JOBS - Twitter may lay off about 300 before Q3 earnings announcement: Report
    10.11.2016 - 0 Comments
    Twitter may cut 8% of its workforce or about 300 people, Bloomberg reported on Monday, citing people…
  • How to Remove Duplicate Files from Windows
    How to Remove Duplicate Files from Windows
    05.07.2017 - 0 Comments
    Duplicate report finders experiment your difficult power for unnecessary duplicated documents and assist…
  • Pebble Time Steel vs. Pebble Steel: The Pebble Brand is DEAD...
    Pebble Time Steel vs. Pebble Steel: The Pebble Brand is DEAD...
    12.02.2017 - 0 Comments
    The Pebble or the Pebble Time? That is the question. Mike takes a look at both to see which is…

Labels

Android Apk Files Android Apps Android Games Apps Apk Files Apps Hack Tricks Entertainment Free Internet Freecharge Gadgets Games Apk Files How To's Laptops Guide Mobiles Reviews Technology Viral's android zone free recharge

Entertainment

Tricks

Popular Posts

  • Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Refer & ...
  • Hands-on with the home windows 10 Creators update for the Xbox One: Beam recreation streaming arrives
    The Windows ...
  • Now A trip to Mars could give you cancer according to new research
    There’s ...
  • Meet Bat Bot, the new flying batlike drone
    Holy drone ...
  • Xiaomi Mi LED Smart TV 4 Review
    As a brand in ...
  • Facebook co-founder learned programming language in 2 days www.goandroidapps.in
    Facebook co-founder learned programming language in 2 days www.goandroidapps.in
    Facebook co-founder ...
  • Intel's Cannon Lake laptop chip shipments can also slip into next yr
    If you were ...

Random Posts

  • Have you upgraded to iOS 10.three? right here are all the new functions your iPhones and iPads gets
    Have you upgraded to iOS 10.three? right here are all the new functions your iPhones and iPads gets
    30.03.2017 - 0 Comments
    Apple has officially launched the latest version of its iOS -- iOS 10.3. The OS goes public…
  • Habits that causes your hair split ends – How to avoid split ends
    Habits that causes your hair split ends – How to avoid split ends
    15.03.2016 - 0 Comments
    Split ends are one of the most well known hair problems faced by most of the women in the nation. The…
  • To bring 5G network in India Nokia collaborates with Airtel, BSNL
    To bring 5G network in India Nokia collaborates with Airtel, BSNL
    10.04.2017 - 0 Comments
    India’s largest telco Airtel and state-run telco BSNL have joined hands with…
  • New LG G6 is the first phone to come with Dolby Vision
    New LG G6 is the first phone to come with Dolby Vision
    01.03.2017 - 0 Comments
    The LG G6 might not be a 4K phone but it will be the first phone to get Dolby…
  • The way to delete your WhatsApp account permanently
    The way to delete your WhatsApp account permanently
    25.04.2017 - 0 Comments
    WhatsApp today is like a lifeline to its users. With over 1 billion users, the chat app…

Most Popular

  • Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Offer 2018: Refer and Earn Flipkart Vouchers Free
    Teen Patti Refer & ...
  • SAMSUNG GALAXY J7 (2016) REVIEWS
    SAMSUNG GALAXY J7 (2016) REVIEWS
    SAMSUNG GALAXY J ...
  • Top 5 Best SmartPhones under 7000 Rs (March 2017)
    Looking for the ...
  • Apple, IBM, Cisco are huge because of Indians, do not deny them H-1B visa: RBI Governor Urjit Patel
    ...
  • SAMSUNG GALAXY J7 (2016) Specifications
    SAMSUNG GALAXY J ...
  • BlackBerry Teases Marshmallow Beta Testing for Priv by Next Week
    Blackberry ...
  • LG Q6 Review
    LG Q6 Review
    2017 is ...

Contact Form

Name

Email *

Message *

Offers Zone

Created By Android Century Distributed by Android Century
  • Home
  • About us
  • Contact us
  • Privacy policy
  • Terms of use
  • Advertise here
Subscribe Via Email Subscribe To Android Century By Email And Get Free Updates. ;-)


Your email address is safe with us!