. @RBI is single handledly responsible for this #Cybersecurity failure which is going to blow up sooner / later.
Everyone who signed up in #SIHub - Please cancel your cards like *NOW*
---
RT @logic
Once you read the @TheKenWeb story by @tam_arund on #RecurringPayments - update from #SIHub - is
1. Not only they haven't had Privacy Policy and ToS
2. They actually added a reCAPTCHA (in an unresponsive fashion) - which means - they were get…
https://twitter.com/logic/status/1524323623196307462
#cybersecurity #SIHub #RecurringPayments
#WorldConsumerRightsDay #FairDigitalFinance #HallOfShame - For having the most numb product team and keeping the website without a privacy policy / terms of service, ~6 months after being flagged by malware vendors as phishing site - @billdesk #SIHub -
---
RT @logic
So its almost a month, but #SIHub doesn't care about getting itself removed from Phishing database - that is because there is no privacy policy / terms of use!!.
The domain lis…
https://twitter.com/logic/status/1460854438042636288
#WorldConsumerRightsDay #FairDigitalFinance #hallofshame #SIHub
Just like how #RecurringPayments created new intermediaries #SIHub #MandateHQ for processing mandates, #CoFT introduces new intermediaries when you want to use "Saved Cards" from any merchant. #JusPay is one such #CoFT service provider.
#RecurringPayments #SIHub #MandateHQ #CoFT #JusPay
Just like how #RecurringPayments created new intermediaries #SIHub #MandateHQ for processing mandates, #CoFT introduces new intermediaries when you want to use "Saved Cards" from any merchant. #JusPay is one such #CoFT service provider.
#RecurringPayments #SIHub #MandateHQ #CoFT #JusPay
The number of #SIHub mandates is a proxy metric for digital illiteracy and efficacy of awareness campaigns.
We are risking people though for this.
---
RT @AndyRei67311989
Axis bank's official SMS and email channels have given messages to a senior citizen reg an autopay facility via sihub, which looks like the perfect phising site (t&c, privacy links don't work yet asks for cc number) https://www.sihub.in/managesi/axisbank
https://twitter.com/AndyRei67311989/status/1459579499490824195
So its almost a month, but #SIHub doesn't care about getting itself removed from Phishing database - that is because there is no privacy policy / terms of use!!.
The domain list has now propogated to antivirus solutions now.
---
RT @David_Das
Dear @SBICard_Connect trying to edit recurring transaction, antivirus is blocking this url https://www.sihub.in/sso/sbicard - saying its a phising url + its trying to download .ico file. I am una…
https://twitter.com/David_Das/status/1460549161498165250
So cards now got their collect request spam! But this also means card numbers have leaked, travelled far and wide. Please block your card if you get one of these SMS. #CashlessConsumer
---
RT @yubi_bharath
For Microsoft Business worth Rs. 1000000 recurring mandate. What nuts is this? I haven't intiated this mandate. Is my data safe with you, Care to Explain @KotakBankLtd ? @internetfreedom @digitaldutta #sihub
https://twitter.com/yubi_bharath/status/1459378257527140353
https://threatcenter.crdf.fr/criteria.html This is CRDF criteria for flagging malicious link.
1. @billdesk #SIHub Citibank URL got flagged because SIHub has none.
2. @Razorpay #MandateHQ will get flagged because its a 3rd party generic policy they link.
The #SIHub implementation is so shady - that #OSINT researcher have flagged the URL https://www.sihub.in/managesi/citi (which is legit URL sent by @Citibank to its card holders) as suspicious URL