Credit brokerage

Massive data leaks at Check24 and Verivox

Nachrichten
18.09.2024 08:26

The Chaos Computer Club has uncovered massive data leaks at the loan brokerage services of Check24 and Verivox in Germany. At times, loan agreements could be downloaded from both comparison portals, including income information and bank account numbers. 

"Anyone could see where the users live, how many children they have, where they work, what they earn and how much money they are currently spending on loans," CCC spokesperson Matthias Marx told the media outlet Correctiv.

Verivox announced that the data leak had been closed immediately after the CCC's tip-off. With the exception of the whistleblower, no unauthorized access to the data had been detected. "We therefore assume that no damage has been caused to our customers." The Baden-Württemberg data protection officer is investigating the incident.

Check24 initially left inquiries unanswered but, according to Correctiv, has also rectified the error, found no unauthorized access to the files and retrained its employees.

"Bumbling handling" of customer data
According to the CCC, an IT expert first discovered the vulnerabilities at Check24 in July. He then checked the competitor site Verivox and found similar vulnerabilities there. They should have been noticed during every check. According to Correctiv, he speaks of a "botched handling" of customer data: "Actually, the term 'security gap' is almost inappropriate here, as in both cases the data was simply openly accessible via the Internet."

According to the report, there was a second security breach at Check24, which required more IT expertise. According to Correctiv, customer data with download links to PDF files with loan offers from the banks were then revealed.

"They contained information such as name, gender, telephone number, email address, date of birth, nationality, employment relationship, length of employment with the current employer, how long the person has lived at their current place of residence, net household income, whether they have already taken out loans, whether they live in rented accommodation, the number of children they have and the number of vehicles they own. Further details of the loan offers were the requested loan amount, installments and account information including IBAN."

Extent of potential damage unknown
The two companies were informed via the CCC. It is unclear how long the leak lasted and how many users were potentially affected. According to Correctiv, data records of 75,000 people may have been accessible at Verivox. According to experts, however, there are no indications that data from those affected was distributed, traded or used criminally online.

Check24 customers in Austria not affected
Check24 Austria CEO Florian Reichert pointed out in a statement that users of the portal in this country were not affected by the data leak. "We work with independent IT structures and also operate as an independent company in Austria. Our systems are comprehensively protected, are constantly checked and meet the highest security standards," said Reichert.

 

This article has been automatically translated,
read the original article here.

 krone.at
krone.at
Loading...
00:00 / 00:00
play_arrow
close
expand_more
Loading...
replay_10
skip_previous
play_arrow
skip_next
forward_10
00:00
00:00
1.0x Geschwindigkeit
Loading
Kommentare
Eingeloggt als 
Nicht der richtige User? Logout

Willkommen in unserer Community! Eingehende Beiträge werden geprüft und anschließend veröffentlicht. Bitte achten Sie auf Einhaltung unserer Netiquette und AGB. Für ausführliche Diskussionen steht Ihnen ebenso das krone.at-Forum zur Verfügung. Hier können Sie das Community-Team via unserer Melde- und Abhilfestelle kontaktieren.

User-Beiträge geben nicht notwendigerweise die Meinung des Betreibers/der Redaktion bzw. von Krone Multimedia (KMM) wieder. In diesem Sinne distanziert sich die Redaktion/der Betreiber von den Inhalten in diesem Diskussionsforum. KMM behält sich insbesondere vor, gegen geltendes Recht verstoßende, den guten Sitten oder der Netiquette widersprechende bzw. dem Ansehen von KMM zuwiderlaufende Beiträge zu löschen, diesbezüglichen Schadenersatz gegenüber dem betreffenden User geltend zu machen, die Nutzer-Daten zu Zwecken der Rechtsverfolgung zu verwenden und strafrechtlich relevante Beiträge zur Anzeige zu bringen (siehe auch AGB). Hier können Sie das Community-Team via unserer Melde- und Abhilfestelle kontaktieren.

Kostenlose Spielechevron_right
Vorteilsweltchevron_right