Dear XYZ customers,
We are writing to inform you about a data security issue that may involve your XYZ account information.
PayHere (pvt) Ltd, our payment gateway partner for online transactions, issued a press release on xx/yy/zzzz informing about a data compromise that occurred from their systems as a result of the cyberattack on PayHere on the 2nd of April 2022. Please read their full incident report here.
LINK
Considering the sensitive nature of the compromised data, we recommend all our customers reset their passwords as a precautionary measure. PayHere management has ensured us that they have taken all the necessary steps to tighten their security on multiple levels to prevent any future attacks. The management also communicated that there will not be any financial risk due to the compromised data.
Rest assured that we will keep you informed about any new developments of this data breach.
XYZ Customer Service Team
First question comes from the Customer
"What about my existing data are they being used in somewhere else? " then you fucked
communicated that there will not be any financial risk due to the compromised data.
We talking about someone else money and this statement is not true. why you taking unnecessary risk? this is not your fault. and you don't know the Extend of this attack and either payshere telling the truth
So i would defiantly send my customers
"Until we sort things out do not use the payment system"
I don't know why WSO2 or MIT come up with a safe payment platform as they have way more experience than some random tech company
I give you one reason
Because of the Security involve in this technologies most of the technologies has to learn their self and even get the Dev help from vender by signing some agreements. there is no help in StackOverflow , GitHub or anywhere else when you try to program. so you must have at lest 4-5 years of industry experience on this area in order to successfully implement a Payment system
------
Post added on May 3, 2022 at 10:26 PM