SBI Website hacked, no data loss

December 29, 2008
By sinha

SBI website, www.sbi.co.in was hacked on Dec 25th – though the site has been restored, the transaction features are not yet enabled and will take another few weeks to conduct transactions at the site.

What’s interesting to note is that SBI wants to avoid the word ‘hacking’ and is calling the disruption ‘technical problem‘ – again, a case of not informing users whether their data is safe or not.

The bank has three million Net banking users. If you are one, did you receive any mailer from SBI informing the issue (i.e. technical snag?)

Do you feel comfortable hearing about the hacking from third party sources (and not the bank itself?)?

Tags:

               About the author - Ashish Sinha is a Startup Mentor/Product Strategy Coach, and the founder/chief editor of pluGGd.in. He has launched/managed couple of products (consumer as well as enterprise) in US and India, and now consults with startups/small businesses on their product/media strategy. He can be reached at: ashish (at) pluGGd.in [+91 98452 06443]

38 Responses to “ SBI Website hacked, no data loss ”

  1. neha on December 29, 2008 at 3:05 pm

    sarkari bank hain ya sarkari chor …?

    • Ashish on January 5, 2009 at 6:29 pm

      Dear,

      Statebankofindia.com or sbi.co.in is only informational portal in which bank’s information is provided. For trasanction SBI has Onlinesbi.com which is fully safe even in the comparison with any bank. So before making any comments improve ur knowledge bank.

      • playboy.playboy1988 on October 7, 2009 at 6:06 pm

        not safe i have hack it once

        • ashish on October 7, 2009 at 10:14 pm

          Good Joke.. i like it…

          • Vikash Saini on October 30, 2009 at 1:27 pm

            sir,
            i am agree with you.
            u are write SBI website is most secured than other banks and people should not worry about it.

            –to all :- please don’t make any unproved comment

      • BINAY on March 9, 2010 at 11:34 pm

        I agree with you. What anybody can get by hacking statebankofindia.com or sbi.co.in And onlinesbi.com is fully secure.

        Its all about conspiracy against SBI.

    • kgg on August 2, 2009 at 10:59 pm

      gr8 comment…

    • playboy.playboy1988 on October 7, 2009 at 6:06 pm

      chor he chor

      • ashish on October 7, 2009 at 10:16 pm

        one side u r saying u hv hacked & other side blaming to bank…seems confusing…ek to chori uper se seenajori..Very good..

  2. Sharda Balaji on December 29, 2008 at 3:17 pm

    This certainly gives sleepless nights…
    SBI’s internet banking features and safety is considered to be the best, even by other bankers.
    I know of a really large private bank which discussed the BKMs (Best Known Methods) from SBI when they wanted to start i-banking in India.

    I bank with SBI…did not get any email from the bank though! :( (

  3. Rizwan on December 29, 2008 at 5:12 pm

    I am telling you, this is a conspiracy by other banks to bring SBI down as they have been amongst the very few banks who have not been hit that hard by the economic slow down. Its these bankers who want to bring it down…. :)

    Jus kidding, someone found out a loophole and tried to exploit it and SBI shut down the system to prevent misuse.

    Please keep us posted if you find any more news on this

  4. Amit Aggarwal on December 29, 2008 at 5:13 pm

    today, I did a transaction at onlinesbi.com and it went smoothly. also, didn’t get any email from them regarding any technical issues..

  5. Amit Bagree on January 3, 2009 at 6:56 am

    Ohh no surprises. I was at SBI sometime back to reset my password. I was shocked when I saw someone walk in with their (online) password written on a piece of paper to reset their (profile) password and he gave it to the SBI lady who after using it, just threw the paper in the dustbin instead of shredding it.
    This apart few other things really annoyed me-
    1. Why do you have to physically go to a branch office to reset your online banking password? This is the first bank I have ever heard to implement something like this.
    2. Why would you have to pay Rs 200 to reset your online password? After all even if they are primitive with their online system, it still takes just a few clicks to reset a password, right?
    3. Another one of those – “God knows why” you would design a site which requires a user to remember two passwords, there are better ways of doing two factor authentication if they really care about security.
    I can keep on going but over a period of time I have sort of lost faith in getting any customer service from public sector cos. Not to say that private sector cos’s are any better. Just a matter of choosing the bad amongst the worsts.

    • Ashish on January 5, 2009 at 6:37 pm

      Please tell me the branh name and city which is chaging to reset password. I got reset the passord free of cost.

      • Amit Bagree on January 8, 2009 at 12:32 pm

        Ashish this is the main SBI branch in Nagpur right next to the railway station also known as Kingsway Branch. Now there are two passwords: the login password & the profile password. If you remember your profile password then you can retrieve your login password free of cost. However, if you don’t remember your profile password you pay Rs. 200 to reset it as per the SBI staff. Are we both talking of the same password?

        • Ashish on January 12, 2009 at 11:07 am

          Can u provide me ur mail id for further communication?

          • Amit Bagree on January 12, 2009 at 2:37 pm

            Absolutely. I sent you an email.

          • Amit Bagree on February 2, 2009 at 4:14 am

            Hey I’m sorry I mistook you for the other Ashish & sent an email to him instead. You can contact me at amit_bagree[at]yahoo.co.in. ttysoon…

      • Rakesh on August 1, 2009 at 12:19 am

        In Gurunanak Branch,Vijayawada,AP they chareged Rs:100/- to reset my password.
        This is Ridiculous.

        • Amit on March 15, 2010 at 2:08 am

          Same here. The Central Branch in Nagpur charges Rs100 for a password change. Shameless ….. I found out something new today – The change email functionality on the “My Profile” page doesn’t work either. I guess I have to go to the branch to change that too? which begs the question why have net banking at the first place …

    • BINAY on March 9, 2010 at 11:26 pm

      1. You have to visit your branch for resetting of password just because of security of your online account otherwise any hacking expert can hack your account if he knows your some personal informations.
      2.your userid and password is provided free of cost for the first time only, from the next time you have to pay some nominal fee, it is mainly to avoid unnecessary password resetting requests, to inculcate financial discipline among its customers and to make customers remember their passwords.
      3. Not only two password policy is in existence but also other ways of authentication is available in onlinesbi for added security features.Thats why onlinesbi is more secure than others.

  6. Anoop on January 15, 2009 at 12:07 pm

    1. The initial userid/password was provided by a letter from the bank. After two months of obtaining the account details i tried to login for the first time and am getting “Invalid userid and password” .I tried the correct id a few times with the same result.

    2. I tried to log a complaint by providing my detail and message.The online complaint form page it wouldn’t accept the branch name even though I was selecting the branch name from a drop-down box.

    • Ashish on January 20, 2009 at 11:23 am

      You may contact to branch, they will sort out your problem or directly write a complaint to “inb.customer@sbi.co.in”, this mail is already provided in your kit.

  7. Ashish on January 20, 2009 at 11:50 am

    Is there any other problem related to SBI internet banking?

  8. SBI Website Hacked « TechChase on March 17, 2009 at 2:42 pm

    [...] December 29, 2008 As I have mentioned in one of my previous articles “Application Security: The Missing Pillar of Software Quality” in software development (SDLC) process security testing is most overlooked aspect of testing. Critical Web application security problems must be taken care while developing any web application. Biggest bank like SBI are also troubled at times.SBI website, http://www.sbi.co.in was hacked on Dec 25th – though the site has been restored, the transaction features are not yet enabled and will take another few weeks to conduct transactions at the site.What’s interesting to note is that SBI wants to avoid the word ‘hacking’ and is calling the disruption ‘technical problem‘ – again, a case of not informing users whether their data is safe or not.The bank has three million Net banking users. If you are one, did you receive any mailer from SBI informing the issue (i.e. technical?).Via:http://www.pluggd.in [...]

  9. Pankaj on May 2, 2009 at 10:06 pm

    Even is such forum, kindly do not share your email ids….it may be used by someone to do phishing for you…be an alert citizen

  10. S Venugopal on June 2, 2009 at 8:56 am

    I have received a new Password for internet banking. Now the problem is that I could not login with my new password eventhough my User ID is correct.

    • BINAY on March 9, 2010 at 11:01 pm

      Please contact the branch either personally or telephonically stating your account no., user id and internet banking envelope (given for password) number. Please note after resetting of login password your user id remains the old one and password got changed to new one provided in envelop. The user id printed in envelope mean nothing to you.

  11. Rakesh on August 1, 2009 at 12:24 am

    How to get Profile password, at the time of internet banking activation they given me only account UserName and Password. Know I require profile password. Could you please suggest me how to get that.

  12. ashish on August 1, 2009 at 10:46 pm

    at first login u will have to create new username, password & profile password.

  13. Bimaya on August 21, 2009 at 7:08 am

    For the first time I logged in to SBI netbanking. Successfully I could change the login id and password but the problem is in profile password.I tried a lot but it couldn’t.*already I have fallowed all instruction .So anyone will guide me from their experience.

    • ashish on August 21, 2009 at 10:11 pm

      are u following the password policy carefully which is given in kit. try one more time…

  14. Pankaj on September 3, 2009 at 9:07 pm

    I am not able to login and do not know what is profile password.

  15. Surajit(SilenceSpeaker) on November 10, 2009 at 4:23 pm

    its not working……. fake….

    I want to real hack sbi and get much more money. I love money

  16. Surajit BaRik ( SilenceSpeaker) on November 10, 2009 at 4:24 pm

    try to hacck………..

  17. Mriganka Nath on February 10, 2010 at 5:25 pm

    Activation Problem

    Sir,

    I got my internet banking kit from my branch on 9th Feb 2010.
    But till now I am not able to login. It says “Invalid username and password”.
    Plz activate my online banking account as soon as possible.
    The State Bank should improve their service before promising anything.

    My account details:

    Acc no: – 10282037080
    Branch-South Guwahati
    Dist-Kamrup (Assam)
    Internet banking user ID – 14065375
    Kit No. 6421912607
    Packet No. 64219
    Circle Code: 12
    Serial No. 60

    Thanking You

    Mriganka Nath
    Cell-09706422629
    Guwahati-781007
    Assam

    • Ashish on February 10, 2010 at 10:48 pm

      Don’t you thinnk u r becoming too liberal to share ur information over Internet…Dear kindly put ur complaint to inb.customer@sbi.co.in.

    • BINAY on March 9, 2010 at 11:08 pm

      Just call your branch and tell them the problem. Your account will be activated within 24 hours. You can also complaint over inb.customer@sbi.co.in

Leave a Reply

By hitting 'Submit' button, you agree to our commenting policy [meant for anonymous cowards]