Skip to content
NGTEdu Logo

NGTEdu

A PRODUCT OF NGTECH.CO.IN

NGTEdu Logo

NGTEdu

  • Home
  • Cyber Attacks
  • Malware
  • Vulnerabilities
  • Data Breach
  • Home
  • Cyber Attacks
  • Copied master key forces South African bank to replace 12 million cards
  • Critical Vulnerability
  • Cyber Attacks
  • Data Breach
  • Vulnerabilities

Copied master key forces South African bank to replace 12 million cards

6 years ago Graham Cluley
Copied master key forces South African bank to replace 12 million cards

Fraudsters stole more than $3.2 million from the banking division of South Africa’s post office, after – in a catastrophic breach of security – employees printed out the bank’s master key.

According to South African media reports, the security breach occurred in December 2018 when a copy of Postbank’s digital master key was printed out at a data center in Pretoria.

According to internal documents acquired by journalists, employees stole the 36-digit master encryption key, which “allows anyone who has it to gain unfettered access to the bank’s systems, and allows them to read and rewrite account balances, and change information and data on any of the bank’s 12-million cards.”

The security breach went unnoticed for months, giving fraudsters free reign to steal millions of dollars. In the nine months up to December 2019, the fraudsters are thought to have used the copied master key to access accounts without authorisation, and make over 25,000 fraudulent transactions, mostly from cards used by people receiving social benefits from the government.

A problem for Postbank is that all of the cards were generated with the compromised master key. The bank believes that replacing all of the cards will cost in the region of $58 million.

The bank has conducted an internal security audit following the breach, and suspects that rogue employees are responsible.

According to news reports, South Africa’s Reserve Bank last year gave Postbank an 18 month deadline to replace the compromised cards. The bank has also responded to the breach by prohibiting contactless offline transactions for cardholders.

Many questions remain unanswered regarding how the master key was secured, such as whether the key had been divided into separate parts stored separately – requiring collusion between different people to reveal it in its entirety, and what measures Postbank (not to be confused with the German bank of the same name) had taken to keep tight control of such a critical asset.

But clearly something went very wrong at the very heart of the bank if it was possible for someone to make off with a copy of such an essential part of its security as its master key, and then exploit it to make fraudulent transactions. The natural suspicion has to be that the fraud was orchestrated with the assistance or knowledge of privileged insiders within the bank, rather than tech-savvy hackers just happened to stumble across a piece of paper containing a printout of the bank’s master key.

All too often organisations are more focused on the threat posed by external hackers and ignoring the risks presented by partners, contractors, and rogue members of staff.

Insiders have advantages over malicious external hackers for a variety of reasons. An insider threat can be tough to detect and remain undetected for years, sometimes indistinguishable from regular work activities.

An insider has often been given special privileges to work alongside sensitive data, making it harder to know if what they are doing is malicious or not. Furthermore, it’s much easier for a rogue employee to cover their tracks than an external hacker, destroying evidence that otherwise might later be used against them, or blaming incompetence rather than malicious intent for any breach that occurs.


Editor’s Note: The opinions expressed in this guest author article are solely those of the contributor, and do not necessarily reflect those of Tripwire, Inc.

The post ” Copied master key forces South African bank to replace 12 million cards” appeared first on TripWire

Source:TripWire – Graham Cluley

Tags: Critical Severity, Exploit, Finance, Hacker, TripWire

Continue Reading

Previous Amazon Web Services Mitigated a 2.3 Tbps DDoS Attack
Next Phishing Campaign Targeting Office 365, Exploits Brand Names

More Stories

  • Cyber Attacks
  • Data Breach
  • Vulnerabilities

FBI Warns Russian Hackers Target Signal, WhatsApp in Mass Phishing Attacks

1 day ago [email protected] (The Hacker News)
  • Critical Vulnerability
  • Cyber Attacks
  • Data Breach
  • Vulnerabilities

Oracle Patches Critical CVE-2026-21992 Enabling Unauthenticated RCE in Identity Manager

1 day ago [email protected] (The Hacker News)
  • Critical Vulnerability
  • Cyber Attacks
  • Data Breach
  • Malware
  • Vulnerabilities

CISA Flags Apple, Craft CMS, Laravel Bugs in KEV, Orders Patching by April 3, 2026

1 day ago [email protected] (The Hacker News)
  • Cyber Attacks
  • Data Breach
  • Malware

Trivy Supply Chain Attack Triggers Self-Spreading CanisterWorm Across 47 npm Packages

1 day ago [email protected] (The Hacker News)
  • Cyber Attacks
  • Data Breach
  • Malware
  • Vulnerabilities

Trivy Security Scanner GitHub Actions Breached, 75 Tags Hijacked to Steal CI/CD Secrets

2 days ago [email protected] (The Hacker News)
  • Critical Vulnerability
  • Cyber Attacks
  • Data Breach
  • Malware
  • Vulnerabilities

Critical Langflow Flaw CVE-2026-33017 Triggers Attacks within 20 Hours of Disclosure

2 days ago [email protected] (The Hacker News)

Recent Posts

  • FBI Warns Russian Hackers Target Signal, WhatsApp in Mass Phishing Attacks
  • Oracle Patches Critical CVE-2026-21992 Enabling Unauthenticated RCE in Identity Manager
  • CISA Flags Apple, Craft CMS, Laravel Bugs in KEV, Orders Patching by April 3, 2026
  • Trivy Supply Chain Attack Triggers Self-Spreading CanisterWorm Across 47 npm Packages
  • Trivy Security Scanner GitHub Actions Breached, 75 Tags Hijacked to Steal CI/CD Secrets

Tags

Android APT Bug CERT Cloud Compliance Coronavirus COVID-19 Critical Severity Encryption Exploit Facebook Finance Google Google Chrome Goverment Hacker Hacker News High Severity Instagram iPhone Java Linux Low Severity Malware Medium Severity Microsoft Moderate Severity Mozzila Firefox Oracle Patch Tuesday Phishing Privacy QuickHeal Ransomware RAT Sim The Hacker News Threatpost TikTok TripWire VMWARE Vulnerability Whatsapp Zoom
Copyright © 2020 All rights reserved | NGTEdu.com
This website uses cookies to improve your experience. We'll assume you're ok with this, but you can opt-out if you wish. Read More here.Cookie settingsACCEPT
Privacy & Cookies Policy

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these cookies, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may have an effect on your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
Non-necessary
Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.
SAVE & ACCEPT