26 Feb 2026, Thu

Theft of crores of rupees caught in YES Bank’s prepaid Forex card, how did the hackers loot without CVV?

Yes Bank Fraud Case: The issue of irregularities in IDFC First Bank has not been resolved yet, but now Yes Bank has informed about some suspicious transactions related to its prepaid forex card. The bank found that there has been a data breach in its BookMyForex Multi-Currency Forex Card.

Fraud committed through 15 merchants

According to the Bank’s fraud monitoring system, several cases of sudden abnormal transaction decline or increase in rejections were reported in some of the Bank’s multi-currency prepaid Forex cards issued in association with BookMyForex. The fraud monitoring system found that hackers used bank identification numbers (BIN) for transactions without customers’ permission.

The investigation found that between 3:30 am and 8:30 am (Indian time) on February 24, 2026, all the illegal transactions were done through 15 merchants from a Latin American country. Since in many Latin American countries like Brazil, OTP or two-factor authentication is not required for online shopping etc. In such a situation, the hackers chose those 15 merchants of Latin America, where OTP is not required for online payment, hence the money was deducted from the card even before the customers got the alert.

Used BIN Attack

In this sequence, cards of 5000 customers were tampered. To carry out this fraud, hackers used BIN Attack. Based on the first 6-8 digits of the card, hackers guess the remaining digits, card expiry date and CVV and as soon as the software finds a correct number, the hackers come to know that the card is active and then they commit fraud by doing a big transaction with that card.

theft worth crores

The hackers chose the time between 3:30 to 8:30 pm Indian time because most of the people in India are sleeping at this time. In such a situation, he did not even know about the alert coming on his mobile. Later, when this information was received, a large number of customers complained about illegal foreign transactions on social media platforms like X and Reddit. In total, around Rs 2.55 crore ($0.28 million) was stolen.

RBI summoned

After this incident related to data breach, Reserve Bank of India (RBI) has summoned senior officials of Yes Bank. Here Yes Bank has said that the loss to the affected 5000 customers will be compensated through chargeback. Meanwhile, keeping in mind the convenience of the customers, the bank has not only blocked the facility of making payments on those specific foreign websites, but has also increased the monitoring of about 1.9 lakh cards.

What is a Prepaid Forex Card?

This is a kind of card which is not directly linked to your bank account. It is especially used while traveling abroad. In this you can load or deposit foreign currency like dollar, euro, pound from India itself. Its biggest feature is that on using normal Indian credit or debit cards abroad, there is an extra markup charge of 3-5%, whereas on Forex cards it is either zero or very less.

Also read:

Will rooftop solar panels become expensive now? Trump’s new order increases headache

Source link

By Admin

Leave a Reply

Your email address will not be published. Required fields are marked *