TSB's online banking platform left several customers unable to access their own accounts, yet able to view other people.
Claims the problem is now fixed, however several of the bank’s customers were still reporting issues with one claiming to have been credited with £13,000, which did not belong to him.
Many customers had already taken to Twitter to complain about not being able to log into their online banking accounts or being able to transfer funds and make payments.
Source: https://www.information-age.com/tsb-chaos-online-banking-data-leak-123471613/
TPRM report: https://scoringcyber.rankiteo.com/company/tsbbank
"id": "tsb11524622",
"linkid": "tsbbank",
"type": "Data Leak",
"date": "04/2018",
"severity": "85",
"impact": "3",
"explanation": "Attack with significant impact with internal employee data leaks"
{'affected_entities': [{'customers_affected': 'Multiple',
'industry': 'Banking',
'name': 'TSB Bank',
'type': 'Financial Institution'}],
'attack_vector': 'Application Vulnerability',
'data_breach': {'type_of_data_compromised': 'Personal Account Information'},
'description': "TSB's online banking platform left several customers unable "
"to access their own accounts, yet able to view other people's "
'accounts. Claims the problem is now fixed, however several of '
'the bank’s customers were still reporting issues with one '
'claiming to have been credited with £13,000, which did not '
'belong to him. Many customers had already taken to Twitter to '
'complain about not being able to log into their online '
'banking accounts or being able to transfer funds and make '
'payments.',
'impact': {'brand_reputation_impact': 'Negative',
'customer_complaints': ['Unable to log in',
'Unable to transfer funds',
'Unable to make payments'],
'data_compromised': 'Personal Account Information',
'operational_impact': 'Unable to access accounts, transfer funds, '
'and make payments',
'systems_affected': 'Online Banking Platform'},
'response': {'communication_strategy': ['Public Statement',
'Social Media Engagement']},
'title': 'TSB Online Banking Platform Incident',
'type': 'Data Breach'}