Sensitive Data Stolen in Hack on Poland’s SuperGrosz Lending Platform

505     0
Sensitive Data Stolen in Hack on Poland’s SuperGrosz Lending Platform
Sensitive Data Stolen in Hack on Poland’s SuperGrosz Lending Platform

Poland’s digital affairs minister said data from SuperGrosz users was stolen in a cyberattack and handed to criminals. Response teams are investigating; officials promised a tool to check if individuals were affected.

Data from users of the SuperGrosz lending portal was stolen in a cyberattack and “ended up in the hands of criminals,” Poland’s deputy prime minister and digital affairs minister Krzysztof Gawkowski said on X. He called the situation “very serious” and said cyber security incident response teams CSIRT KNF and CSIRT NASK were handling the case.

Gawkowski said the stolen data included “e-mail addresses, first and last names, information on nationality, PESEL numbers [Poland’s national ID], identity card data, residential and mailing addresses, phone numbers, information on marital status, number of children, employment status, the name, address, tax ID (NIP) and phone number of the employer, declared industry and income, bank account numbers, [and a] Facebook portal identifier.”

The minister urged SuperGrosz customers to take immediate precautions: freeze their PESEL numbers in the mObywatel government app, change passwords, and enable two-factor authentication on all accounts. Polish authorities have likewise recommended two-factor authentication (2FA) and heightened vigilance for phishing attempts.

SuperGrosz is operated by AIQLABS, a company offering quick online loans. The operator confirmed on its website that a hacker attack enabled unauthorized remote access to part of its customer database through code created by the attackers. It said some data was stolen with a high risk of online disclosure, reported the incident to CSIRT KNF, CSIRT NASK and the data protection authority, and would email affected users. The company also posted information in the “Bezpieczne Dane” service.

The Polish Press Agency (PAP) reported that national incident response teams were engaged and that the matter had been escalated to data protection authorities, reiterating the minister’s description of the situation as “very serious.”

The breach comes amid a string of recent cyber incidents in Poland. On November 1, payment system BLIK reported service disruptions caused by a distributed denial-of-service (DDoS) attack.

The travel agency Nowa Itaka also disclosed a breach affecting some account data—such as email addresses and, in some cases, names and phone numbers—while saying booking, financial, participant and password data were not affected.

Лица: Гавковский Кшиштоф, Krzysztof Gawkowski
Теги: Фишинг, Персональные данные, AIQLABS, SuperGrosz, Утечка данных, Власть, кибератаки
Регион: Польша

Читайте по теме:

Польша намерена создать «дрон-зоны» для охраны объектов критической инфраструктуры
Государство национализировало мусорного оператора в Ивановской области на 5,6 миллиарда рублей
В США задержали родственницу пресс-секретаря Белого дома из-за просроченной визы
В Ростове массовые перебои с мобильным интернетом
Италия ввела в уголовный кодекс отдельную статью о фемициде, предусматривающую пожизненное заключение
Бывший менеджер «Аэрофлота» Михаил Минаев осуждён за растрату более 3,8 миллиарда рублей на лизинговых сделках
Жители России столкнутся с увеличением коммунальных платежей до 22% сразу после выборов
Обманутые дольщики «Стрижей» в Томске годами ждут свои квартиры после банкротства застройщика
В Перми раскрыто хищение более 100 миллионов рублей на оборонном заводе «Машиностроитель»
Новая волна обмана: жертвы сами звонят мошенникам, ущерб вырос до 65 миллиардов рублей