India Found Cyber Security Lapses In NPCI In 2019

A government audit of India’s flagship payments processor last year found more than 40 security vulnerabilities including several it called “critical” and “high” risk, according to an internal government document seen by Reuters.

The audit, which took place over four months to February 2019, highlighted a lack of encryption of personal data at the National Payments Corporation of India (NPCI), which forms the backbone of the country’s digital payments system and operates the RuPay card network championed by Prime Minister Narendra Modi.

The March 2019 government document cited the storing of 16-digit card numbers and other personal information such as customer names, account numbers and national identity numbers in “plain text” in some databases, leaving the data unprotected if the system was breached. The audit has not previously been reported.

The NPCI said in a statement to Reuters it is regularly audited in the interests of security and senior management reviews all findings, which are then “remediated to (the) satisfaction of the auditors”. This includes the findings cited by Reuters, it said.

India’s National Cyber Security Coordinator, Rajesh Pant, whose office coordinated the audit, also said in a statement to Reuters that “all observations raised in last year’s report have been confirmed as resolved by the NPCI”.

Pant added audits are best practice for the mitigation of cyber attacks and are conducted on a periodic basis by all enterprises.

The audit was undertaken to provide Modi’s National Security Council with an overview of the NPCI’s defences against cyber attacks. Modi’s office and the finance ministry did not respond to a Reuters request for comment.

The audit’s findings underscore the data-security challenges faced by the NPCI which processes billions of dollars daily via services that include inter-bank fund transfers, ATM transactions and digital payments.

In India and beyond, financial institutions are under immense pressure to mount effective defences to protect their customers as the number of malicious cyber attacks grows and hackers become more sophisticated.

Set up in 2008, the NPCI is a not-for-profit company which as of March 2019 counted 56 banks as its shareholders, including the State Bank of India, Citibank and HSBC.

RuPay, in particular, has been enthusiastically endorsed by Modi, who has likened its use to a national duty. It has grown to account for almost two-thirds of nearly 900 million debit and credit cards issued in India as of October, according to NPCI and central bank data.

Recent Posts

  • Featured

Zohran Mamdani’s Last Name Reflects Eons Of Migration And Cultural Exchange

Zohran Mamdani, the 34-year-old New York State Assembly member and democratic socialist, was elected New York City’s mayor on Nov.…

1 hour ago
  • Featured

What Makes The Indian Women’s Cricket World Cup Win Epochal

For fans and followers of women’s cricket, November 2 – the day the ICC World Cup finals were held in…

7 hours ago
  • Featured

Dealing With Discrimination In India’s Pvt Unis

Caste-based reservation is back on India’s political landscape. Some national political parties are clamouring for quotas for students seeking entry…

9 hours ago
  • Featured

‘PM Modi Wants Youth Busy Making Reels, Not Asking Questions’

In an election rally in Bihar's Aurangabad on November 4, Congress leader Rahul Gandhi launched a blistering assault on Prime…

1 day ago
  • Featured

How Warming Temperature & Humidity Expand Dengue’s Reach

Dengue is no longer confined to tropical climates and is expanding to other regions. Latest research shows that as global…

1 day ago
  • Featured

India’s Tryst With Strategic Experimentation

On Monday, Prime Minister Narendra Modi launched a Rs 1 lakh crore (US $1.13 billion) Research, Development and Innovation fund…

1 day ago

This website uses cookies.