Standard Bank hit by data leak

mylesillidge

Journalist
Joined
Jul 29, 2021
Messages
4,274
Reaction score
4,576
Standard Bank suffers data leak

Standard Bank says it has been impacted by an incident in which personal information of clients was subject to "unauthorised access" on 23 March 2026, with external experts now investigating.

The bank, the largest in South Africa by assets, told MyBroadband that the unauthorised access did not impact its banking systems, which remain secure and operational.
 
People that still bank with Substandard bank deserve it.
 
That doesn't help. Where do you save the encryption keys when you need that data?

It is just passing the buck around.
Yip, these guys go through all the pain of compliance projects to protect the data but in the end they need to access it as well so at some point its all in the clear.

My thing is... if someone gets onto the server hosting the data then the battle is already lost. You can bog your system down with excessive encryption and hoops to jump but it all does it make it harder to access your own data
 
There was also an incident about Standard Bank's business customers who had their data stolen by an employee I believe not too long ago. Like last year?
 
I wonder if I can tell them to shove their FICA update requirement so that I can do what I need to with my bond... since they can't keep their data secure why must I jump through hoops for nothing if they are going to leak data and stuff anyway. lol
 
Developer: The code we just wrote got breached. We need to fix it ASAP.
ChatGPT: You're right — we didn’t implement proper security controls. Let’s refactor it with authentication, input validation, and—

a few minutes later
System: You’ve reached your usage limit for this model.


Developer: Please fix the security issue. ChatGPT wrote code with no security.
Claude: I understand your concern. Let’s take a thoughtful, step-by-step approach to improving the system’s security posture. First, we should consider the broader architectural implications…
Developer: …can you just fix the bug?
Claude: Absolutely. Here is a 3,000-word analysis of potential vulnerabilities. Which should we fix first?
 
Banks in ZA spend stupid amounts being "compliant"

The trick being compliance != secure

Compliance, especially from a security point of view, is utter bullshiat. It just makes auditors - at least audit partners - rich.
 
Banks in ZA spend stupid amounts being "compliant"

The trick being compliance != secure

Compliance, especially from a security point of view, is utter bullshiat. It just makes auditors - at least audit partners - rich.
And they often have ... less than epic people ... doing the work.

We were doing an integration into the one bank... We were supposed to send some files over via API.
The developer that was doing the work at the bank sent me over the info...
API endpoint //jnbserver-01/webapi/fileupload ....

I replied "hey man I need either a public IP or a url that is public facing because I can't access it from outside your network"

Broksi skiets back with "I tried it from another pc and it works fine"... BRUH

Eventually he wanted to get a WLAN or some leased line between the two locations and I was like "hol up bruv we do an FTP thing for another process, can we not just dump files in a different folder."

----------
Back in the day I thought that you had to be TOP NOTCH to do work for the banks... but I've heard some stories of kak that goes on there....
 
FICA is not a "their" requirement. That is very much a cANCer brainfart
Also true... but like RICA, it only frustrates legitimate clients while we still have RAMPANT fraud around sims and stuff.

It probably helps a bit... but at this point there are too many people in positions where they can circumvent those regulations that they are a frustration and not an actual helpful mechanism anymore.
 
Top
Sign up to the MyBroadband newsletter
X