Indian online ID verification firm Signzy confirms security incident

Date:

Share post:


Signzy, a popular vendor offering online “know your customer” ID verification and customer onboarding services to several top financial institutions, commercial banks, and fintech companies, has confirmed a security incident, TechCrunch can exclusively report.

The Bengaluru-based startup, which serves over 600 financial institutions globally — including the four largest Indian banks, was hit by a cyberattack last week, according to sources speaking with TechCrunch. On Saturday, Signzy told TechCrunch it was aware of the security incident but declined to elaborate.

India’s computer emergency response team, known as CERT-In, separately acknowledged TechCrunch that it was aware of the incident and “in process of taking appropriate action with the concerned authority.”

Founded in 2015, Signzy enables onboarding for 10 million customers and businesses monthly. The startup, which has offices in New York and Dubai — in addition to its India offices in Bengaluru, Gurugram, and Mumbai — counts several major companies among its key customers, including ICICI Bank, SBI, MSwipe, and Aditya Birla Financial Services.

TechCrunch learned about the security incident from sources, including two Signzy clients, who were concerned about the alleged customer data that briefly appeared on a cybercrime forum post, which TechCrunch has seen.

PayU, another Signzy customer, said that Signzy was hit by an “information stealer malware” and asserted that it had no exposure to the incident.

“There is no impact on PayU customers or their data due to Signzy’s information stealer malware. We have received written confirmation from the vendor that PayU and its customers’ data have not been compromised and remain secure with the best security standards in place,” PayU spokesperson Dimple Mehta told TechCrunch.

Other customers said they were unaffected. When asked by TechCrunch, ICICI Bank stated that it had no exposure to the incident.

In a statement to TechCrunch, Signzy declined to comment on whether customer data had been exfiltrated. Debdoot Majumder, a spokesperson representing Signzy, said the company had hired a “professional agency for conducting the security incident investigation.”

The startup, backed by investors including Mastercard, Vertex Ventures, Kalaari Capital, and Gaja Capital, said it had informed its clients, regulators and stakeholders about the security incident.

When asked if the firm had engaged with the Reserve Bank of India, the country’s central bank, Signzy said it had no communication. The central bank didn’t respond to a request for comment.



Source link

Lisa Holden
Lisa Holden
Lisa Holden is a news writer for LinkDaddy News. She writes health, sport, tech, and more. Some of her favorite topics include the latest trends in fitness and wellness, the best ways to use technology to improve your life, and the latest developments in medical research.

Recent posts

Related articles

Cleerly raises $106M from Insight Partners for AI heart health early detection

Although heart disease is the leading cause of death in the United States, a significant portion of...

A billionaire private astronaut and SpaceX supporter may be the next NASA head

Incoming President Donald Trump has nominated Jared Isaacman, a billionaire entrepreneur and private astronaut, to lead NASA...

OpenAI inks deal to upgrade Anduril’s anti-drone tech

OpenAI plans to team up with Anduril, the defense startup, to supply its AI tech to systems...

Non-profit 1863 Ventures has closed, reborn into for-profit New Majority Ventures

The nonprofit organization 1863 Ventures, which focused on providing capital and mentorship to early-staged underrepresented founders, will...

LLMs may have a killer enterprise app: ‘digital labor’ — at least if Salesforce Agentforce is any indicator

If Don Draper from “Mad Men” was quintessentially, at his deepest self, an ad man, then Salesforce...

The pope gets his first electric popemobile from Mercedes-Benz

Mercedes-Benz has delivered the first all-electric popemobile to the Vatican: a modified version of the German automaker’s...

Spotify users are disappointed by an underwhelming Wrapped this year

After weeks of anticipation, some Spotify users are left underwhelmed by the streamer’s personalized year-in-review feature, Spotify...

Threads users can now follow profiles from other fediverse servers

A new update from Meta’s X competitor Instagram Threads allows users to connect more with the fediverse,...