To the attention of Luke Prior,
Entelgy Innotec Security manages the fraudulent actions against Santander (Openbank) and all issues related to security incidents against this company.
We have detected that there are sensitive information leaked, without authorization, from the following URL(s):
https://github.com/LukePrior/open-banking-tracker.git
https://raw.githubusercontent.com/LukePrior/open-banking-tracker/f6a1f2a3387cd7a9f247164f443e3e1be592ba1e/brands/product/25797662-e294-ea11-a831-000d3a8842e1/872ab7a8-5f9f-4d1a-b79f-84d7abf69393.json
https://raw.githubusercontent.com/LukePrior/open-banking-tracker/e14f09324609e57032b400d33104e67b937de80e/brands/product/d5306c4e-ea83-ec11-a82b-000d3a884a20/AC_onlinesavings.json
Evidences:
https://ibb.co/bJkqmhN
https://ibb.co/N3yt9R5
Lines:
|
"self": "https://openbank.newcastlepermanent.com.au/cds-au/v1/banking/products/AC_onlinesavings" |
|
"self": "https://openbank.api.nab.com.au/cds-au/v1/banking/products/872ab7a8-5f9f-4d1a-b79f-84d7abf69393" |
In this repository, in the file "products", corporate URLs used by interconnection APIs of apps and servers that have been leaked appear. This leaked information represents a risk to the security of our client, Banco Santander (Openbank). This information is not available publicly elsewhere, should have been kept confidential and its public availability could pose a security risk to our client, as these URLs could be the target of attacks like DDoS, exploitation of vulnerability, etc.
As you can see in this evidence, the name Openbank appears 241 times in this repository:
Evidence: https://ibb.co/T4j8TDr
We request the elimination of the information related to Santander (Openbank) from this repository.
This unauthorized use of restricted information represents a security risk of Santander. We need your collaboration to stop this leaked information incident, by getting offline this content from the reported the URL(s). If you need more information regarding this incident, please contact our CSIRT 24/7 by replying to this email.
Thank you very much for your attention. Looking forward to your reply.
Regards,
Juan Esteban GarcΓa Flood
CSIRT | Entelgy Innotec Security
Email: [email protected]