← Citigroup

2011 Online banking breach — 360k cardholders

2011 360.0K records affected Share on X

Data compromised

Email addresses, Names, Addresses, Account numbers, Transaction history

Technical writeup

Hackers exploited a vulnerability in customer website; inserted account numbers into URL to systematically capture data. Names, account numbers, email addresses, and transaction histories exposed.

Root cause

Website vulnerability; URL manipulation allowed unauthorized data access.

References