Eng

Vulnerability exposes 10 million transactions at Indonesia’s largest mobile games payment processor Unipin

KrASIA
更新於 2020年07月22日14:22 • 發布於 2020年07月22日06:22 • Daniel Boltinsky and Cindy Silviana

A data vulnerability at Unipin, one of the largest payment processors for mobile games in Southeast Asia, briefly exposed roughly 10 million user transaction records from gamers, which included usernames, purchase amounts, and email addresses.

When reached for comment, Unipin confirmed the vulnerability from July 3. However, KrASIA was able to verify its existence from at least as early as July 1. The vulnerability allowed anyone to access data—which did not include sensitive information such as real names, log in, or bank account information—by simply entering a compromised URL address.

KrASIA gained access to the vulnerability on July 1.
廣告(請繼續閱讀本文)

“We found a bug that resulted in the accession of a small amount of successful transaction data, such as players’ character names. However, we can ensure that crucial data, for example, customer’s passwords, banking information, or other sensitive data that might jeopardize our user’s privacy, remain safely controlled in the UniPin system,” the spokesperson told KrASIA in the email. “There’s no user’s sensitive data are [sic] being disclosed.”

Garena and NetEase (HKG: 9999), two gaming companies that use Unipin as payment processing partner, declined to comment.

廣告(請繼續閱讀本文)
kr asia community

The leak is reminiscent of recent news involving Indonesian e-commerce unicorns Tokopedia and Bukalapak. In those cases, similar transaction records were leaked, then sold online. Taken together, usernames, transaction amounts, and email addresses can be valuable for hackers for reselling to competitors or, more seriously, for social engineering.

廣告(請繼續閱讀本文)

Unipin’s vulnerability raises questions about the protections in place at payment processors, who—amid the boom in online gaming—sit on mountains of user data.

“The vulnerability at Unipin becomes an example that the information and data security is a global problem, not only in Southeast Asia,” said Sam Ardi, a cybersecurity expert, who was shown a video of the vulnerability by KrASIA. “Security is not only an issue for young users but also the adult generation. Many people haven’t aware of information and data security, especially related to their accounts.”

According to web analytics portal Similarweb, more than 3 million people visited Unipin in May 2020. The platform collects payments on its website for popular mobile games such as Garena’s Free Fire, Moonton’s Mobile Legends, NetEase’s Rules of Survival, VNG’s King of Fighters, Zlongame’s Dragon Raja, and Tencent’s PUBG Mobile.

Unipin operates in Singapore, Indonesia, the Philippines, Malaysia, Thailand, and India.

查看原始文章

更多 Eng 相關文章

Brunei cultural tourism visitors increase 70 percent in 2024
XINHUA
Türkiye's daily oil production reaches 132,000 barrels: minister
XINHUA
Hong Kong stock market sees daily average turnover exceed 200 bln HKD in 2025
XINHUA
Key system of China's next-generation "artificial sun" passes acceptance process
XINHUA
Urgent: China to roll out new policies to support employment of college graduates: official
XINHUA
China's top political advisory body holds closing meeting of annual session
XINHUA
GLOBALink | China reaffirms commitment to reform, opening up at "two sessions"
XINHUA
GLOBALink | @TwoSessions: China advances high-quality development
XINHUA
Flash: China's average life expectancy reaches 79 years in 2024: health official
XINHUA
China, Iran and Russia to conduct joint naval exercise in March
XINHUA
Xinhua News | China vows to ensure timely assistance for people in difficulties
XINHUA
Update: China pledges timely assistance for people in difficulty
XINHUA
Trump golf resort vandalized, spray-painted with "Gaza is not for sale"
XINHUA
Xinhua News | China to roll out new policies to support employment of college graduates: official
XINHUA
"She-power" lights up China's cultural heritage preservation
XINHUA
Chinese NEVs power up Southeast Asia through deepened partnerships
XINHUA
Fact Check: Why is "China threat" narrative invalid?
XINHUA
China will resolutely stabilize real estate market: minister
XINHUA
China vows to ensure timely assistance for people in difficulties
XINHUA
Xinhua News | China will resolutely stabilize real estate market: minister
XINHUA