2016 HDFC Bank debit cards — sector-wide compromise via Hitachi Payment Services processing network
Data compromised
Debit card magnetic-stripe / transaction-path data sufficient for fraud in the reported modus operandi; per-bank field-level breakdown not uniform in open sources
Technical writeup
October 2016 reporting described malware affecting the Hitachi Payment Services (Hitachi Payment Systems) card-processing and switch environment used by multiple Indian banks. Public narratives cited about 3.2 million payment cards exposed across roughly nineteen banks, with State Bank of India, HDFC Bank, ICICI Bank, Axis Bank, and YES Bank widely named among the heaviest impacted issuers; fraud patterns included overseas card-not-present abuse. HDFC Bank was routinely listed in mainstream coverage as reissuing or blocking cards as part of the industry response. Institution-specific card reissue totals were not uniformly itemized in early press relative to the aggregate industry figures.
Root cause
Malware in third-party payment switch / processing infrastructure (Hitachi Payment Services) serving multiple Indian banks
References
- https://en.wikipedia.org/wiki/2016_Indian_Banks_data_breach
- https://www.hindustantimes.com/business-news/this-is-how-3-2-million-debit-cards-in-india-were-compromised/story-BHsFrKK076cHYu4SRx2VjN.html
- https://www.bitdefender.com/en-us/blog/hotforsecurity/3-2-million-debit-cards-compromised-in-indian-hack