Menu
Browse

Cyber Incident Victim: Punjab National Bank

Date:

Nov 2021

Location:

India

Summary

A cybersecurity firm alleged that Punjab National Bank exposed personal and financial data of over 180 million customers for seven months due to security vulnerabilities, compromising funds and sensitive information. The bank denied any data breach or system compromise, asserting compliance with ISO 27001 information security standards, but the cybersecurity firm publicly disputed these claims as false and misleading.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 2 motives 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

The Punjab National Bank (PNB) faced public allegations of a significant data breach on November 21, 2021, when cybersecurity firm CyberX9 published a blog post claiming the bank had compromised the security of funds, personal data, and financial information belonging to all 180 million of its customers. CyberX9 asserted this security lapse had persisted for seven months, exposing sensitive customer assets to potential exploitation. Media outlets amplified these claims in reports published on November 21, prompting PNB to issue a formal denial the following day. The bank categorically stated no breach of its systems had occurred and no customer or account holder data had been pilfered. PNB emphasized its adherence to ISO 27001 standards for information security management, positioning this certification as evidence of robust security practices.

Cyber Incident Image

CyberX9 swiftly challenged PNB’s denial, characterizing it as "false and misleading" in subsequent public statements reported by BusinessToday.in. This rebuttal intensified the dispute without providing additional technical evidence of data exfiltration or system intrusion. The conflicting narratives created uncertainty regarding the actual security status of customer data, though no independent verification of either party’s claims was documented in available reports. PNB maintained its position that customer information remained secure, while CyberX9 insisted the bank’s systems were vulnerable. The incident generated media attention focused on the credibility of both the bank’s security assurances and the cybersecurity firm’s initial findings, though conclusive evidence confirming a breach or quantifying potential impacts remained absent from public disclosures.

Sources
Sources available to members
1 source