India's CERT-In warns fintechs NBFCs payment providers of API attacks
Heads-up: India's cybersecurity agency, CERT-In, is warning fintechs, NBFCs, and payment service providers about cyberattack campaigns targeting payment APIs.
Hackers are finding ways to sneak past security checks on internet-facing applications and exposed APIs, aiming for unauthorized money transfers by misusing gateway and bank credentials.
CERT-In advises multifactor authentication, API hygiene
CERT-In recommends stepping up security: think multifactor authentication everywhere, keeping track of all your APIs, shutting down anything unused, and swapping out static tokens for safer options.
They are also urging real-time monitoring and strict transaction limits.
If something shady pops up, the advice is clear: freeze affected accounts or APIs quickly, save any evidence, and let CERT-In know right away.