Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Abuse][Santander] [C178021] Cooperation to remove sensitive information posted on GitHub Inc #478

Open
Csirtas opened this issue Nov 13, 2023 · 0 comments

Comments

@Csirtas
Copy link

Csirtas commented Nov 13, 2023

To the attention of the repository owner ,

Innotec Security manages the fraudulent actions against Santander and all issues related to security incidents against this company.

We have detected that your service is being used to publish leaked sensitive information without authorization, from the following URL(s):

https://github.com/fintecturegit/open-banking-tracker-data/blob/master/data/account-providers/santander-mx.json

  • Corporate URLs used by interconnection APIs of apps and servers that have been leaked.

This information is not available publicly elsewhere, should have been kept confidential and whose public availability could pose a security risk to our client, as these URLs could be the target of attacks like DDoS, exploitation of vulnerability, etc.

In addition, according to the international ISO standard: ISO 27001:2013 A.18.1.3.: "Records shall be protected from loss, destruction, falsification, unauthorized access, and unauthorized release, in accordance with legislative, regulatory, contractual, and business requirements".

This unauthorized use of restricted information represents a security risk of Santander. We need your collaboration to stop this leaked information incident, by getting offline this content from the reported the URL(s). If you need more information regarding this incident, please contact our CSIRT 24/7 by replying to this email.

Thank you very much for your attention. Looking forward to your reply.

Regards,

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant