Indian pharmacy chain giant exposed customer data and internal systems


A major Indian pharmacy chain operated a flawed platform which exposed highly sensitive data of millions of users, experts have warned. DavaIndia Pharmacy, the pharmacy arm of Zota Healthcare, currently runs more than 2,300 stores across the country – however, its platform was bugged in a way that allowed unauthenticated users to create “super admin” accounts.

These accounts came with high privileges, allowing the attackers to access extremely sensitive information: they could exfiltrate customer information (including health conditions, medications, and other private purchases), tamper with product listings (they could modify the entries and prices), change which drugs required a doctor’s prescription, and more.

Read more…
Source: TechRadar News


Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox


Related:

  • Cisco to train 250,000 students in India in cyber security, IoT

    April 12, 2017

    Aiming to help create startups and build successful technology careers, Cisco will train 2,50,000 students in the country over a period of time, a top executive from the global networking giant said. “We have done a lot of work in education and there are campuses that use our technology. We will skill 250,000 students in the ...

  • In line with PM Modi’s push, Army gets new software to enhance cyber security

    April 2, 2017

    In line with Prime Minister Narendra Modi‘s push for enhancing cyber security, the Indian Army is testing the indigenous BOSS (Bharat Operating System Solutions) to guard its communication and information networks from espionage by foreign players. In his maiden address to the senior commanders of the three services, the prime minister had asked them to guard ...