Full News

RBI, FEMA & BANKING

E-commerce Hacking: Safeguards for Companies and Users

E-commerce Hacking: Safeguards for Companies and Users

The recent e-commerce hacking incident involving a criminal defrauding a website for Rs 4.16 crore has raised concerns about cyber security measures. This incident highlights the importance of implementing robust safeguards for both companies and users to protect against cyber attacks.

Key Takeaways:

  • Companies should conduct Vulnerability Assessment and Penetration Testing (VAPT) on their websites regularly.
  • Security background checks on developers are essential to ensure the development of secure e-commerce websites.
  • Adherence to regulatory standards such as PCI DSS certification is crucial for companies.
  • Users should exercise caution when encountering suspicious offers or reward points on e-commerce websites.
  • Verification of PCI DSS certification is recommended for users to ensure secure payment processing on websites.


The recent hack involving a criminal defrauding a website for Rs 4.16 crore by hacking into a company called Reward360 and creating fake bank vouchers has raised concerns about the cyber security measures of e-commerce websites. This incident highlights the importance of implementing robust safeguards for both companies and users to protect against such cyber attacks.

Safeguards for Companies

1. Vulnerability Assessment and Penetration Testing (VAPT): Companies should regularly conduct VAPT on their websites. VAPT involves hiring a third-party organization proficient in auditing to test the website’s security by simulating cyber attacks and identifying vulnerabilities.


2. Security Background Checks on Developers: It is essential for companies to perform security background checks on developers who are involved in developing e-commerce websites. This ensures that the developers are knowledgeable about secure coding practices and can build and maintain secure websites.


3. Compliance with Regulatory Standards: Companies should adhere to regulatory standards such as the Payment Card Industry Data Security Standard (PCI DSS) certification. Websites that are PCI DSS certified have met global standards for secure payment processing.

Safeguards for Users

1. Cautiousness of Suspicious Offers or Reward Points: Users should be vigilant of suspicious offers or reward points, especially if they seem too good to be true. They should exercise caution when encountering such offers and verify the legitimacy of the website.


2. Verification of PCI DSS Certification: Users should look for websites that are PCI DSS certified, as this certification indicates that the website has met global standards for secure payment processing.

Impact on Users

In the event of a security breach, users’ data may be compromised, leading to potential identity theft or unauthorized access to personal information. If a user’s data is affected, the company is obligated to notify the user and provide compensation as per the new data privacy law. The company may also face penalties for the breach.

Oversight of Cyber Hygiene

The Reserve Bank of India (RBI) plays a crucial role in overseeing the cyber hygiene of financial transactions and e-commerce platforms. RBI mandates that companies dealing with financial transactions must undergo regular security assessments, such as VAPT, conducted by third-party independent security companies. However, it is important for companies to ensure that they engage multiple independent security companies to thoroughly test their websites and submit comprehensive reports to RBI.

User Caution

Users are advised to exercise caution when using e-commerce websites. They should look for the PCI DSS certification logo on websites, which indicates compliance with global security standards. Additionally, users should be wary of new websites and ensure that reputable payment gateways, such as Razorpay or Paytm, are used for transactions.


In conclusion, the recent e-commerce hacking incident underscores the importance of implementing stringent security measures for both companies and users to mitigate the risks associated with cyber attacks and safeguard sensitive data and financial transactions.

FAQ

Q1: What safeguards should companies and users take to protect against e-commerce hacking?

A1: Companies should conduct regular VAPT, perform security background checks on developers, and adhere to regulatory standards such as PCI DSS certification. Users should be cautious of suspicious offers and verify the PCI DSS certification of e-commerce websites.


Q2: What should users do if they suspect an e-commerce website has been hacked?

A2: Users should look for signs of a website hack, such as homepage replacement, and exercise caution when encountering unusual offers or reward points. They should also verify the PCI DSS certification of the website.


Q3: What are the potential impacts of e-commerce hacking on users?

A3: In the event of a security breach, users’ data may be compromised, leading to potential identity theft or unauthorized access to personal information. Companies are obligated to notify affected users and provide compensation as per data privacy laws.