Payhere, helapay සහ helakuru දත්ත උල්ලංඝනය කිරීම්, ආරක්ෂාව සහ පෞද්ගලිකත්ව අවදානම් Payhere, helapay & helakuru data breaches, security & privacy risks

Roxburyroy

Well-known member
  • Jul 24, 2023
    3,556
    3,958
    113
    Payhere යනු 2016 දී දියත් කරන ලද ශ්‍රී ලාංකේය මාර්ගගත ගෙවීම් ද්වාර සේවාවකි. එය ක්‍රෙඩිට් කාඩ්පත්, ජංගම මුදල් පසුම්බි සහ බැංකු හුවමාරු භාවිතා කරමින් ගනුදෙනුකරුවන්ගෙන් ගෙවීම් භාර ගැනීමට වෙළඳුන්ට ඉඩ සලසයි. Payhere ප්‍රොක්සි මගින් PCI DSS අනුකූල වන ශ්‍රී ලංකාවේ ප්‍රථම සහ එකම ගෙවීම් ද්වාරය බවට හිමිකම් කියයි, එයින් අදහස් වන්නේ එය සිය සේවාදායකයන් මත කිසිදු ක්‍රෙඩිට් කාඩ් විස්තරයක් ගබඩා කිරීම හෝ සැකසීම සිදු නොකරන අතර, ඒ වෙනුවට එහි හවුල්කාර බැංකු (සම්පත් බැංකුව සහ සෙලාන් බැංකුව) මත රඳා පවතින බවයි. ) එසේ කිරීමට.

    කෙසේ වෙතත්, 2022 අප්‍රේල් මාසයේදී, payhere විසින් එහි වෙබ් අඩවිය, SMS ද්වාරය, වෙබ් යෙදුම් සහ දත්ත සමුදායන් අවදානමට ලක් කළ විශාල සයිබර් ප්‍රහාරයකට ලක් විය. ප්‍රහාරකයා 'හැක් කරන ලද' දැන්වීමක් සමඟ වෙබ් අඩවියේ ගොඩබෑමේ පිටුව වෙනස් කර ව්‍යාජ පැතිකඩකින් සමාජ මාධ්‍යවල තිර රුවක් පළ කළේය. ප්‍රහාරකයා විසින් ගෙවීම් PCI DSS අනුකූල නොවන බව පවසමින් ජනතාව නොමග යවා ක්‍රෙඩිට් කාඩ් විස්තර හෙළිදරව් කර ඇත. තවද, ප්‍රහාරකයා SMS ද්වාරය පැහැරගෙන ගොස් සමහර වෙළෙන්දන්ට අනතුරු ඇඟවීමක් යවා, 'payhere හැක් කර ඇති බව' ඔවුන්ට දන්වා කාඩ්පත් සම්මුතිය පිළිබඳ වැරදි තොරතුරු නැවත ප්‍රකාශ කළේය.

    Payhere ප්‍රහාරය පිළිගත් අතර හවුල්කාර බැංකුවල සේවාදායකයන් විසින් සකසන ලද බැවින් සම්පූර්ණ ණයපත් අංක කිසිවක් සම්මුතියකට ලක් නොවන බවට මහජනතාවට සහතික විය. කෙසේ වෙතත්, දත්ත කඩවීම් නිරීක්ෂණය කරන වෙබ් අඩවියක් වන Have I Been Pwnd ට අනුව, ගෙවීම් වාර්තා මිලියන 1.5කට අධික ප්‍රමාණයක් හෝ වඩාත් නිවැරදිව 1,580,249ක් ගෙවා ඇත. 65GB වටිනා නිරාවරණ දත්තවලට IP සහ භෞතික ලිපින, නම්, දුරකථන අංක, මිලදී ගැනීමේ ඉතිහාසය, සහ අර්ධ වශයෙන් අපැහැදිලි ණයපත් දත්ත (කාඩ්පත් වර්ගය, පළමු 6 සහ අවසාන ඉලක්කම් 4 සහ කල් ඉකුත්වන දිනය) ඇතුළත් වේ. මෙය ක්‍රෙඩිට් කාඩ්පත් විස්තර සම්මුතියකට ලක්වී නැති බවට ගෙවන ප්‍රකාශයන්ට පටහැනි වේ.

    Payhere හැක් කිරීම ශ්‍රී ලංකා ඉතිහාසයේ විශාලතම දත්ත කඩකිරීම් වලින් එකක් ලෙස සැලකේ. එය වෙළෙන්දන් සහ සේවාව භාවිතා කළ පාරිභෝගිකයින් යන දෙඅංශයෙන්ම බරපතල ආරක්ෂාව සහ පෞද්ගලිකත්ව අවදානම් මතු කරයි. අනන්‍යතා සොරකම්, වංචාව, තතුබෑම්, අයාචිත තැපැල් යැවීම, බ්ලැක්මේල් කිරීම හෝ වෙනත් සයිබර් අපරාධ සඳහා අනිෂ්ට ක්‍රියාකාරීන් විසින් නිරාවරණය කරන ලද දත්ත භාවිතා කළ හැක. අර්ධ වශයෙන් අපැහැදිලි ණය කාඩ්පත් දත්ත තිරිසන් බලය හෝ වෙනත් ශිල්පීය ක්‍රම භාවිතයෙන් සම්පූර්ණ කාඩ්පත් අංක අනුමාන කිරීමට ද භාවිතා කළ හැක. එපමනක් නොව, හෙලිදරව් කරන ලද දත්ත මගින් payhere සහ එහි වෙළෙන්දන්ගේ කීර්ති නාමයට හා විශ්වාසයට හානි කළ හැකි අතර, දත්ත ආරක්ෂණ නීති සහ රෙගුලාසි වලට අනුකූල වීම කෙරෙහි බලපෑම් ඇති කරයි.

    payhere හැක් කිරීම හෙලපයි සහ හෙලකුරු වැනි එහි අනෙකුත් නිෂ්පාදනවල ආරක්ෂාව සහ පෞද්ගලිකත්වය පිළිබඳ ප්‍රශ්න ද මතු කරයි. Helapay යනු payhere මගින් බල ගැන්වෙන සහ ශ්‍රී ලංකා මහ බැංකුව විසින් අනුමත කරන ලද ඩිජිටල් ගෙවීම් ක්‍රමයකි. එය LankaPay ජාතික ගෙවීම් ජාලය හරහා ඔවුන්ගේ ඇඟිලි සලකුණු හෝ මුහුණු හැඳුනුම්පත භාවිතයෙන් ගෙවීම් කිරීමට පරිශීලකයින්ට ඉඩ සලසයි. Helakuru යනු සිංහල යතුරුපුවරු යෙදුමක් වන අතර එය යෙදුම තුළ ගෙවීමේ විකල්පයක් ලෙස helapay ද පිරිනමයි. helapay සහ helakuru දෙකම Payhere හි මව් සමාගම වන Bhasha Lanka (Pvt) Ltd සතු වේ.

    Payhere එහි කඩදාසි රහිත වෙළෙන්දා ඇතුළු කිරීමේ ක්‍රියාවලියේදී අනිෂ්ට මෘදුකාංග ඇතුළත් ගොනු උඩුගත කිරීමක් හරහා උල්ලංඝනය වී ඇති බැවින්, helapay සහ helakuru ද සමාන ප්‍රහාරවලට ගොදුරු විය හැකිය. තවද, helapay සහ helakuru payhere සමඟ ඒකාබද්ධ වී ඇති බැවින්, අනාගතයේ දී payhere හි ඇති විය හැකි දත්ත කඩකිරීම් හෝ සේවා ඇනහිටීම් වලටද බලපෑම් ඇති විය හැක. මීට අමතරව, helapay සහ helakuru සිය පරිශීලකයින්ගෙන් සංවේදී ජෛවමිතික දත්ත (ඇඟිලි සලකුණු හෝ මුහුණු හැඳුනුම්පත) රැස් කරන බැවින්, මෙම දත්ත සුරක්ෂිතව ගබඩා නොකළහොත් හෝ සම්ප්‍රේෂණය නොකළහොත් ඔවුන්ට පුද්ගලිකත්ව අවදානම් ද ඇති කළ හැකිය.

    එබැවින්, සබැඳි හෝ නොබැඳි ගෙවීම් සඳහා payhere හෝ ඒ ආශ්‍රිත නිෂ්පාදන (helapay සහ helakuru) භාවිතා කිරීමේදී පරිශීලකයින් ප්‍රවේශම් වීම සුදුසුය. කිසියම් සැක කටයුතු ගනුදෙනු හෝ ගාස්තු සඳහා පරිශීලකයන් ඔවුන්ගේ ක්‍රෙඩිට් කාඩ් ප්‍රකාශ සහ බැංකු ගිණුම් නිරීක්ෂණය කළ යුතුය. පරිශීලකයන් ඔවුන්ගේ මුරපද වෙනස් කළ යුතු අතර ඔවුන්ගේ සබැඳි ගිණුම් සඳහා ද්වි-සාධක සත්‍යාපනය සක්‍රීය කළ යුතුය. Payhere හෝ එහි හවුල්කරුවන්ගෙන් යැයි කියා ගන්නා සහ පුද්ගලික හෝ මූල්‍ය තොරතුරු ඉල්ලා සිටින ඕනෑම තතුබෑම් ඊමේල් හෝ SMS පණිවිඩ ගැන පරිශීලකයින් ද ප්‍රවේශම් විය යුතුය. පරිශීලකයන් ඒවා භාවිතා කිරීමට පෙර payhere සහ ඊට අදාළ නිෂ්පාදනවල සේවා නියම සහ රහස්‍යතා ප්‍රතිපත්තිය සමාලෝචනය කළ යුතුය.



    Payhere is a Sri Lankan online payment gateway service that was launched in 2016. It allows merchants to accept payments from customers using credit cards, mobile wallets, and bank transfers. Payhere claims to be the first and only payment gateway in Sri Lanka that is PCI DSS compliant by proxy, meaning that it does not store or process any credit card details on its servers, but rather relies on its partner banks (Sampath Bank and Seylan Bank) to do so.

    However, in April 2022, payhere suffered a major cyberattack that compromised its website, SMS gateway, web applications, and databases. The attacker altered the website landing page with a 'Hacked' notice and posted a screenshot on social media from a fake profile. The attacker also misled the public by claiming that payhere was not PCI DSS compliant and that credit card details were exposed. Furthermore, the attacker hijacked the SMS gateway and sent an alert to some of the merchants, informing them that 'payhere is hacked' and repeating the false information about the card compromise.

    Payhere acknowledged the attack and assured the public that no full credit card numbers were compromised, as they were processed by the partner banks' servers. However, according to Have I Been Pwnd, a website that tracks data breaches, the payhere hack exposed over 1.5 million payment records or more precisely 1,580,249. The 65GB worth of exposed data includes IP and physical addresses, names, phone numbers, purchase histories, and partially obfuscated credit card data (card type, first 6 and last 4 digits plus expiry date). This contradicts payhere's claims that no credit card details were compromised.

    The payhere hack is considered to be one of the largest data breaches in Sri Lanka's history. It poses serious security and privacy risks for both the merchants and the customers who used the service. The exposed data can be used by malicious actors for identity theft, fraud, phishing, spamming, blackmailing, or other cybercrimes. The partially obfuscated credit card data can also be used to guess the full card numbers using brute force or other techniques. Moreover, the exposed data can damage the reputation and trust of payhere and its merchants, as well as affect their compliance with data protection laws and regulations.

    The payhere hack also raises questions about the security and privacy of its other products, such as helapay and helakuru. Helapay is a digital payment method that is powered by payhere and endorsed by the Central Bank of Sri Lanka. It allows users to make payments using their fingerprint or face ID through the LankaPay national payment network. Helakuru is a Sinhala keyboard app that also offers helapay as a payment option within the app. Both helapay and helakuru are owned by Bhasha Lanka (Pvt) Ltd, which is the parent company of payhere.

    Given that payhere was breached through a malware-planted file upload during its paperless merchant onboarding process, it is possible that helapay and helakuru could also be vulnerable to similar attacks. Furthermore, since helapay and helakuru are integrated with payhere, they could also be affected by any potential data breaches or service outages of payhere in the future. Additionally, since helapay and helakuru collect sensitive biometric data (fingerprint or face ID) from their users, they could also pose privacy risks if this data is not stored or transmitted securely.

    Therefore, it is advisable for users to exercise caution when using payhere or its related products (helapay and helakuru) for online or offline payments. Users should monitor their credit card statements and bank accounts for any suspicious transactions or charges. Users should also change their passwords and enable two-factor authentication for their online accounts. Users should also be wary of any phishing emails or SMS messages that claim to be from payhere or its partners and ask for personal or financial information. Users should also review the terms of service and privacy policy of payhere and its related products before using them.

    References:

    ¹: PayHere hack leaves over 1.5 million records compromised | ReadMe News
    ²: Ensuring Integrity on PayHere Cybersecurity Incident – PayHere Blog
    ³: Can the Pay Here hack be Sri Lanka's largest data breach? - NewsCutter
    ⁴: හෙළPay - ඩිජිටල් ගෙවීම් ක්‍රමවේදය - හෙළකුරු FACTS - Knowledge base
    ⁵: හෙළPay - ඩිජිටල් ගෙවීම් ක්‍රමවේදය
    ⁶: HelaPay Terms & Conditions

    (1) PayHere hack leaves over 1.5 million records compromised. https://readme.lk/payhere-hack-over-1-million-compromised/.
    (2) Ensuring Integrity on PayHere Cybersecurity Incident. https://blog.payhere.lk/ensuring-integrity-on-payhere-cybersecurity-incident/.
    (3) Can the Pay Here hack be Sri Lanka's largest data breach? - NewsCutter. https://www.newscutter.lk/breaking-...ri-lankas-largest-data-breach-03052022-33952/.
    (4) හෙළPay - ඩිජිටල් ගෙවීම් ක්‍රමවේදය - හෙළකුරු FACTS - Knowledge base. https://facts.helakuru.lk/payment-services/helapay.
    (5) හෙළPay - ඩිජිටල් ගෙවීම් ක්‍රමවේදය. https://www.helapay.lk/.
    (6) HelaPay Terms & Conditions. https://www.helapay.lk/terms.
     

    Nidarshana_k

    Well-known member
  • Feb 19, 2022
    29,894
    1
    51,879
    113
    ප*යාගල
    sorry.com
    මගෙ මොබිටෙල් නම්බර් එකක් තියෙනව ඒක කාටවත් ම දීල නෑ. මුන්ගෙ Gateway එක හරහා පේමන්ට් එකක් කරා අවුරුදු දෙකකට විතර කලින්. එතකොට මම දුන්නෙ මගෙ මොබිටෙල් නම්බර් එක.මීට මාස දෙකකට විතර කලින් අර නම්බර් එකට වට්සැප් හැදුවා මන් . පෙරේදා කෝල් එකක් ආව නයිජීරියන් එසිගෙ පුතෙක් ගෙන්.මම කට් කරල දැම්මා. මෙ අනික් උන්ට ආපුව

    369879166-10161656251724073-8962816850883705748-n.jpg

    370137574-10161656251649073-4903048651038742560-n.jpg
     

    SimMaster

    Well-known member
  • Dec 16, 2015
    9,881
    13,159
    113
    Mama Payhere atha arala damma e kaledima. Dan payhere thiyena web site ekakin wath payments karanne na hack unata passe. Man use karanne Onepay. Unge payment option select karama banking IPG page ekata forward wela payment eka wenne. E nisa Customer ge card details walata issue ekak wenne na kiyala trust ekak thiyenawa. Onepay service ekath aththatama hodai.
     
    • Like
    Reactions: NRTG

    Roxburyroy

    Well-known member
  • Jul 24, 2023
    3,556
    3,958
    113
    මොනවද හුට්ටෝ මේ කියන්නෙ?
    සිංහල වලින් type කරන්න බැහැ බං. English වලින් type කරල translate කරේ. English එක හරි ඒක කියවලා බලන්න. @Solo Rider @Ulti @The Chairman @Honda.putha @rumesh.fbi

    Yeah
    ------ Post added on Aug 28, 2023 at 2:07 PM

    Paymaster eka hodada reload daanna
    ඕක කාගෙද? ඒකත් එයාලගෙම ද?
    ------ Post added on Aug 28, 2023 at 2:08 PM

    මගෙ මොබිටෙල් නම්බර් එකක් තියෙනව ඒක කාටවත් ම දීල නෑ. මුන්ගෙ Gateway එක හරහා පේමන්ට් එකක් කරා අවුරුදු දෙකකට විතර කලින්. එතකොට මම දුන්නෙ මගෙ මොබිටෙල් නම්බර් එක.මීට මාස දෙකකට විතර කලින් අර නම්බර් එකට වට්සැප් හැදුවා මන් . පෙරේදා කෝල් එකක් ආව නයිජීරියන් එසිගෙ පුතෙක් ගෙන්.මම කට් කරල දැම්මා. මෙ අනික් උන්ට ආපුව

    369879166-10161656251724073-8962816850883705748-n.jpg

    370137574-10161656251649073-4903048651038742560-n.jpg
    ඔය data leak එකෙන් ගත්ත details වලින් වෙන්න පුළුවන් තමයි.
    ------ Post added on Aug 28, 2023 at 2:09 PM

    ගන්න අපේ දේ
    කෙළ ගන්න හොඳම එකෙන්
    ------ Post added on Aug 28, 2023 at 2:09 PM

    Mama Payhere atha arala damma e kaledima. Dan payhere thiyena web site ekakin wath payments karanne na hack unata passe. Man use karanne Onepay. Unge payment option select karama banking IPG page ekata forward wela payment eka wenne. E nisa Customer ge card details walata issue ekak wenne na kiyala trust ekak thiyenawa. Onepay service ekath aththatama hodai.
    ඒක හොඳයි. Onepay එක orel එකේ නේද?
    ------ Post added on Aug 28, 2023 at 2:10 PM
     

    Nadun26

    Well-known member
  • Apr 27, 2015
    14,209
    12,742
    113
    38
    මමනම් Use කරන්නේ LOLC එකේ iPay , ලගදි මම Dialog එකේ Genie ගත්තා එකෙන් මටම විතරක් Manager කෙනක් දුන්නා. Genie එකේනම් LKR/USD දෙකම වැඩ
     
    • Like
    Reactions: NRTG

    Roxburyroy

    Well-known member
  • Jul 24, 2023
    3,556
    3,958
    113
    මමනම් Use කරන්නේ LOLC එකේ iPay , ලගදි මම Dialog එකේ Genie ගත්තා එකෙන් මටම විතරක් Manager කෙනක් දුන්නා. Genie එකේනම් LKR/USD දෙකම වැඩ
    Dialog Genie එකේ savings account එකෙන් සල්ලි අතුරුදන් වෙන system issue එකක් තියෙනවා. මටත් එහෙම වෙලා මට App එකේ පෙන්නන්නේ නැහැ, monthly statement එකෙත් නැහැ. මතක තිබ්බ නිසා සල්ලි ටික නැහැ කියලා තේරුනේ. Dispute එකක් file කරලා සල්ලි ටික ආපහු ගත්තා. ඕක මට විතරක් නෙමේ ගොඩ දෙනෙක්ට වෙලා system අවුල් නිසා කිහිප පාරක්ම.

    Up
    ------ Post added on Aug 28, 2023 at 2:32 PM
     

    senewimala1988

    Well-known member
  • Dec 5, 2007
    7,858
    2,695
    113
    Kadawatha, Sri Lanka
    payhere හැක් කිරීම හෙලපයි සහ හෙලකුරු වැනි එහි අනෙකුත් නිෂ්පාදනවල ආරක්ෂාව සහ පෞද්ගලිකත්වය පිළිබඳ ප්‍රශ්න ද මතු කරයි. Helapay යනු payhere මගින් බල ගැන්වෙන සහ ශ්‍රී ලංකා මහ බැංකුව විසින් අනුමත කරන ලද ඩිජිටල් ගෙවීම් ක්‍රමයකි. එය LankaPay ජාතික ගෙවීම් ජාලය හරහා ඔවුන්ගේ ඇඟිලි සලකුණු හෝ මුහුණු හැඳුනුම්පත භාවිතයෙන් ගෙවීම් කිරීමට පරිශීලකයින්ට ඉඩ සලසයි. Helakuru යනු සිංහල යතුරුපුවරු යෙදුමක් වන අතර එය යෙදුම තුළ ගෙවීමේ විකල්පයක් ලෙස helapay ද පිරිනමයි. helapay සහ helakuru දෙකම Payhere හි මව් සමාගම වන Bhasha Lanka (Pvt) Ltd සතු වේ.
    e wage nishpadana th un laga thiyenavada?
     

    Nadun26

    Well-known member
  • Apr 27, 2015
    14,209
    12,742
    113
    38
    Dialog Genie එකේ savings account එකෙන් සල්ලි අතුරුදන් වෙන system issue එකක් තියෙනවා. මටත් එහෙම වෙලා මට App එකේ පෙන්නන්නේ නැහැ, monthly statement එකෙත් නැහැ. මතක තිබ්බ නිසා සල්ලි ටික නැහැ කියලා තේරුනේ. Dispute එකක් file කරලා සල්ලි ටික ආපහු ගත්තා. ඕක මට විතරක් නෙමේ ගොඩ දෙනෙක්ට වෙලා system අවුල් නිසා කිහිප පාරක්ම.


    Up
    ------ Post added on Aug 28, 2023 at 2:32 PM
    එහෙම ද ? , Genie එකේ මගේ සල්ලි එන්නේ Pan Asia Bank එකේ corporate saving account එකකට එකටනම් හරියටම එනවා. iPay අවුල් උනා බන් එක දෙනකොට හිටියා බන් Manager කෙනක් ඌ අයින් වෙලා ගියා උගෙන් පස්සේ සේවකයෙක් දාලා තිබ්බා ඌට තමා මම ඔකොම අවුල් කිව්වේ ඌ අයින් වෙලා ගිහින් දැන් hotline එකේ උන්ට කිව්වා ම උන් ගානකට ගන්නේ නැහැ වෙලාවකට Call Answer කරන්නේ නැහැ Service එක අන්තිමයි උන්ගේ.