Latest Stories

Stay up-to-date with everything at Approach

Publication

Keep your IBAN secret, it could be easily abused!

Publication date

22.05.2019

National press coverage: Approach has discovered a critical flaw in major online shops relating to IBAN

National press coverage: Approach has discovered a critical flaw in major online shops relating to IBAN

They all speak about the flaw with IBAN: DataNews (FR), RTBF (FR), DataNews (NL), Regional IT (FR), …

Your IBAN could be used by anyone to shop online. For example, we successfully bought items for free on Amazon!

Our security experts recently discovered a simple but critical flaw in the payment process of some of the major online shops. Among credit cards and other secure payment methods, they allow their customers to pay by simply providing an IBAN account number. No password, no Digipass, or no other authentication method are required. How it works is that the money is automatically debited from the provided IBAN account number. And the shopped items are delivered.

Want to know more about this?  Read our article written by our cyber security expert Pierre Alexis, with the technical advisory of DIGITEAL.

Read Our Article

OTHER STORIES

Stay on top of cyber security trends with our Annual Pentest Report. Get unmatched insights and practical advice to defend your digital assets.
Discover the latest trends and vulnerabilities in application security with our third edition of the annual penetration testing statistic report. This report focuses on the detection of unique business logic flaws, which can cause significant damage if left undetected.
Download our updated whitepaper on Hackable Intelligence. Discover potential attacks against machine learning based solutions and how to assess your security level.

Contact us to learn more about our services and solutions

Our team will help you start your journey towards cyber serenity

Do you prefer to send us an email?