Sri Lanka 🇱🇰 Pension Department Data Breach – Vulnerability Still Exists and Nobody is Fixing It!
⭕️ "No data lost in cyberattack on Pensions Dept, systems restored" – The Department of Pensions
This is an absolutely false statement.
⭕️ The breach likely wasn’t even caused by sophisticated hacking – it’s probably due to EXPOSED PUBLIC API ENDPOINTS that anyone can access.
⭕️ These endpoint are still open, a person with basic IT knowledge can easily write a simple script with just a few lines of code and extract the entire database. This is basic web scraping, not even "hacking".
⭕️ The department has inadvertently created undocumented public API endpoints that expose their entire database to the world.
⭕️ After the initial data dump on the dark web, the department introduced an OTP authentication. However, this OTP implementation is laughably flawed.
⭕️ The OTP is generated on the front end (your browser) and sent to the back end for "verification." It’s like showing you the PIN on screen and then asking you to type it back. This provides zero actual security while creating dangerous false sense of security.
⭕️ Every W&OP scheme member’s complete data has been compromised: Name, Address, NIC, Phone, Photo, Gratuity amounts and Workplace details. Thousands of retired government employees, military, and police families are affected. (Anyone can enter the generated number shown in your browser and access the information.)
⭕️ Pensioners are prime targets for scams. Scammers now have everything needed to target Sri Lankan pensioners. They can call knowing exact ID numbers, addresses, pension amounts, and workplace history.
Tell your parents/grandparents: NEVER share personal info, OTPs, or card numbers with callers – even if they know your details. Hang up and verify independently.
⭕️ Considering the inclusion of military personnel and public data, this should be considered national security emergency affecting the public servants and most vulnerable citizens and security personnel. Every hour of delay puts more lives at risk.
⭕️Someone needs to immediately shut down the Pensions Department login portal (https://t.co/XpQ0p0mXu7). Conduct a full security audit and notify all affected individuals at once. immediately.
Note: We came across this over 48 hours ago and reported it to the relevant authorities through multiple independent channels capable of independently verifying the information. However, no action has been taken so far, and the vulnerabilities remain unresolved.
#SriLanka #PensionDepartment #DataBreach
#BITCOIN DIDN’T HIT $100,000 YESTERDAY, SO I’M GIVING AWAY $1,000 TO 5 LOYAL FOLLOWERS!
JUST LIKE, RT & FOLLOW ME.
WINNERS WILL BE ANNOUNCED IN 48 HOURS!
If Bitcoin hits $100,000 by end of Feb
I will give $1,000 Bitcoin to 5 people
To join
like this post,
Repost it,
and follow @MaxBrownBTC and me
Send Bitcoin to $100k !!!
TRUMP Election winning giveaway of $2,600 Bitcoin to 10 people will end
in next 24hrs.
To join just like this post, Repost it
and make sure you are following me.
Let’s fcking go !!