Home » today » News » Fraudsters hacked bank protection through the Fast Payment System

Fraudsters hacked bank protection through the Fast Payment System

Fraudsters learned to steal money from accounts in a new way after the introduction of the Fast Payment System (FPS).

The problem became known from the bulletin of the FinCERT division of the Bank of Russia. According to the Kommersant newspaper, when one of the banks was installed in a mobile application for transferring via SBP, a vulnerability was found associated with an open API. It was used by scammers to change the sender’s account.

The scheme was as follows: get the account number by brute-force method, run the mobile application in debug mode, log in as a real client, send a request to transfer funds to another bank and replace the sender’s account in the request. As a result, the credit institution, without checking, sent a team to the SBP to transfer funds.

The name of the bank was not disclosed.

– .

Leave a Comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.