{"id":27784,"date":"2020-08-27T09:50:28","date_gmt":"2020-08-27T06:50:28","guid":{"rendered":"https:\/\/forklog.com\/en\/?p=27784"},"modified":"2025-08-26T23:07:23","modified_gmt":"2025-08-26T20:07:23","slug":"personal-data-of-joom-and-utair-customers-leaked-online","status":"publish","type":"post","link":"https:\/\/u1f987.com\/en\/personal-data-of-joom-and-utair-customers-leaked-online\/","title":{"rendered":"Personal data of Joom and Utair customers leaked online"},"content":{"rendered":"<p>The Center for Monitoring and Responding to Cyber Attacks in the credit and financial sector of the Bank of Russia (FinCERT) and the Visa payment system have alerted banks to a data breach involving 55,000 banking clients&#8217; records. RBC reported, citing sources familiar with the matter.<!--more--><\/p>\n<p>The breach affected data from the international trading platform Joom. The database contains partial card numbers, their expiry dates, information about the payment system and the issuing bank.<\/p>\n<p>Among the data exposed publicly were the details of customers of Sberbank, Raiffeisenbank, Tinkoff Bank, Rosbank and many others.<\/p>\n<p>The database includes personal data \u2014 full names, phone numbers, e-mails and addresses.<\/p>\n<p>Joom confirmed the breach \u2014 it occurred back in March 2020. At that time the company said it was aware of it, but it did not involve information about bank cards.<\/p>\n<p>FinCERT issued warnings only to the banks whose customers&#8217; cards were represented in the database. The lending institutions reacted to the notification in different ways.<\/p>\n<p>Sberbank said it did not locate card data for its own customers in the database. The database contained information on the cards of customers of the company&#8217;s foreign subsidiaries, but they are not at risk, according to Sberbank.<\/p>\n<p>Otkritie tightened controls over card operations for customers affected by the breach. Raiffeisenbank blocked the compromised cards and announced their reissuance; Promsvyazbank said it would do the same.<\/p>\n<p>Representatives of several banks stated that the database did not contain data enabling theft of funds from cards. However, attackers could use the personal data from the database for other kinds of fraud.<\/p>\n<p>Besides the Joom leak, data of Utair customers appeared online in the network in the past days. The database contains more than 530 thousand records with information on documents, addresses, phone numbers, e-mails, customers&#8217; full names and other data.<\/p>\n<p><script async src=\"https:\/\/telegram.org\/js\/telegram-widget.js?11\" data-telegram-post=\"dataleak\/1844\" data-width=\"100%\"><\/script><\/p>\n<p>The data leaked into the network back in 2019 as a result of hacker attacks, said a representative of Utair to <a href=\"https:\/\/roskomsvoboda.org\/62964\/\" target=\"_blank\" rel=\"noopener noreferrer\">\u00abRoskomsvoboda\u00bb<\/a>.<\/p>\n<p>According to him, the attackers could not access customers&#8217; bank cards, and the accounts of passengers in the loyalty program are not at risk.<\/p>\n<p>Earlier last week, in the network <a href=\"https:\/\/u1f987.com\/en\/news\/database-of-235-million-instagram-tiktok-and-youtube-accounts-found-online\">discovered<\/a> an open database containing nearly 235 million profiles of users on Instagram, TikTok and YouTube.<\/p>\n<p><span style=\"font-weight: 400;\">For details on how personal data ends up on the black market, read ForkLog&#8217;s article.<\/span><\/p>\n<blockquote class=\"wp-embedded-content\" data-secret=\"hZz17sA5PV\">\n<p>How the data black market works: who sells, who buys, and can you protect yourself<\/p>\n<\/blockquote>\n<p><iframe loading=\"lazy\" class=\"wp-embedded-content\" sandbox=\"allow-scripts\" security=\"restricted\" style=\"position: absolute; visibility: hidden;\" title=\"\u201cHow the data black market works: who sells, who buys, and can you protect yourself\u201d \u2014 ForkLog\" src=\"https:\/\/u1f987.com\/exclusive\/kak-ustroen-chernyj-rynok-dannyh-kto-prodaet-kto-pokupaet-i-mozhno-li-zashhitit-sebya\/embed#?secret=78jA1stLmv#?secret=hZz17sA5PV\" data-secret=\"hZz17sA5PV\" width=\"500\" height=\"282\" frameborder=\"0\" marginwidth=\"0\" marginheight=\"0\" scrolling=\"no\"><\/iframe><\/p>\n<p>Subscribe to ForkLog updates on Telegram: <a href=\"https:\/\/t.me\/forklogfeed\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">ForkLog Feed<\/a> \u2014 the full slate of news, <a href=\"https:\/\/telegram.me\/forklog\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">ForkLog<\/a> \u2014 the most important news and polls.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The Bank of Russia\u2019s FinCERT and the Visa payment system alerted banks to a data breach affecting 55,000 banking clients\u2019 records, RBC reported, citing sources familiar with the situation.<\/p>\n","protected":false},"author":1,"featured_media":27785,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"select":"1","news_style_id":"","cryptorium_level":"","_short_excerpt_text":"","creation_source":"","_metatest_mainpost_news_update":false,"footnotes":""},"categories":[3],"tags":[1229,1188,1256],"class_list":["post-27784","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news-and-analysis","tag-banks-and-fintech","tag-data-breach","tag-privacy-and-personal-data"],"aioseo_notices":[],"amp_enabled":true,"views":"36","promo_type":"1","layout_type":"","short_excerpt":"","is_update":"","_links":{"self":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts\/27784","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/comments?post=27784"}],"version-history":[{"count":1,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts\/27784\/revisions"}],"predecessor-version":[{"id":27786,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/posts\/27784\/revisions\/27786"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/media\/27785"}],"wp:attachment":[{"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/media?parent=27784"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/categories?post=27784"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/u1f987.com\/en\/wp-json\/wp\/v2\/tags?post=27784"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}