The Scale of the Hack
According to this notice on Twitter, the attackers broke in and defaced the website before transferring large volumes of data to their servers. The notice also says the stolen data includes the database dump and the source code which they are planning to release on Twitter later today. There’s no way to verify the credibility of these claims, unfortunately. According to this notice on PayHere’s official Facebook page, the attackers have compromised their SMS Gateway as well.
The notice suggests the attackers might have gotten away with PII or personally identifiable information (contact numbers, email addresses, etc.) of anyone who made payments through the PayHere IPG. That means if you have ordered products and services from an e-commerce website designed to receive payments through PayHere, chances are high your PII is already compromised. It is difficult however to accurately assess the scale of the hack based solely on the word of the attackers.
The Gravity of the Hack
According to the attackers, the payment gateway is not compliant with “PCI DSS” and PayHere has lied about its security. Companies like PayHere must comply with 12 requirements to receive the PCI DSS certification. I do not know which one of these requirements PayHere failed to follow. If they lied, however, from now on we have to think twice before providing our payment card details to businesses using the PayHere IPG to accept payments online.
Another concern is that leading financial institutes on the island such as Sampath Bank and Seylan Bank have forged partnerships with PayHere in the past. The extent to which these banks are linked with PayHere is not clear at the moment. Nevertheless, we cannot completely rule out the possibility of the networks owned by these banks getting compromised in the event PayHere gets hacked again. Such incidents have happened before. Consider how the retail giant Target was hacked, if you need an example.
Response from PayHere
pay here in a lousy Tweet and a Facebook post announced they are under attack but the developers are active in resolving the issue. There was no formal announcement or press release, however. They reassured payment card details were not exposed but did not comment on the fate of the personally identifiable information. Did they inform the SLCERT? I have no idea! Frankly speaking, I feel PayHere management is not doing enough to warn their end-users or the customers of those end-users.
I am a frequent buyer at Jump Books an online bookshop that uses the PayHere IPG to accept card payments on its website. Hence it’s possible the attackers were able to compromise my own personally identifiable information and that of many others. Unfortunately, not even Jump Books alerted me to the incident. They should have but they did not. There is a notice on their checkout page saying “PayHere Online payment gateway is temporarily disabled due to a technical issue from our payment partner” and that’s it.
Source :
https://www.yoshlk.me/technicity/payhere-hack/