{"id":20042,"date":"2021-05-27T18:50:45","date_gmt":"2021-05-27T16:50:45","guid":{"rendered":"http:\/\/159.69.82.204\/win\/?p=20042"},"modified":"2022-06-22T09:13:22","modified_gmt":"2022-06-22T07:13:22","slug":"zahlungsdienstleister-klarna-fremde-konten-einsehbar","status":"publish","type":"post","link":"https:\/\/borncity.com\/win\/2021\/05\/27\/zahlungsdienstleister-klarna-fremde-konten-einsehbar\/","title":{"rendered":"Data leak at Fintech Klarna: Third-party accounts viewable"},"content":{"rendered":"<p><img decoding=\"async\" title=\"Sicherheit (Pexels, allgemeine Nutzung)\" style=\"float: left; margin: 0px 10px 0px 0px; display: inline\" alt=\"Sicherheit (Pexels, allgemeine Nutzung)\" src=\"https:\/\/www.borncity.com\/blog\/wp-content\/uploads\/2021\/04\/Sicherheit_klein.jpg\" width=\"200\" align=\"left\">[<a href=\"https:\/\/www.borncity.com\/blog\/2021\/05\/27\/zahlungsdienstleister-klarna-fremde-konten-einsehbar\/\" target=\"_blank\" rel=\"noopener\">German<\/a>]I already know why I don't let financial service providers or fintechs access my bank accounts via app. According to media reports, Swedish payment service provider Klarna experienced a serious data protection breach. Users who used the Klarna app were able to view the data and transactions of third-party users for a short time this Thursday morning (May 27, 2021). The provider took the app offline after the data breach became known.<\/p>\n<p><!--more--><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" alt=\"\" src=\"https:\/\/vg09.met.vgwort.de\/na\/528367a9faf444afb4ed72cb7a0469f1\" width=\"1\" height=\"1\">Klarna <\/a>is a Swedish payment provider headquartered in Stockholm. The company offers payment solutions in the e-commerce sector. Its core service is to take merchants' payment claims and process their customer payments from that point on. According to the company, a total of 200,000 online merchants in 17 countries use Klarna, meaning that 90 million end consumers use the company's payment methods. On its website, Klarna promotes its app that can make shopping smarter (Smooth Shopping). Favorite items can be saved and shared, purchases can be managed and paid for &#8211; and as a carrot, there are sale alerts and deals. <\/p>\n<h2>The data breach<\/h2>\n<p>I became aware of the serious data breach via the following <a href=\"https:\/\/twitter.com\/BleepinComputer\/status\/1397936266939973633\" target=\"_blank\" rel=\"noopener\">tweet<\/a>, which has since been confirmed by Swedish payment service provider Klarna. <\/p>\n<blockquote>\n<p><a href=\"https:\/\/status.klarna.com\/incidents\/dzydcsh9sbqr\">Disruption to the Klarna consumer app<\/a>  <\/p>\n<p><strong>Monitoring<\/strong> &#8211; Klarna log in is now available for all platforms in all locations.<br \/><small>May <var>27<\/var>, <var>17:47<\/var> CEST<\/small>  <\/p>\n<p><strong>Update<\/strong> &#8211; Consumers can now login to Klarna at app.klarna.com. We will provide further updates regarding our mobile apps in the near future.<br \/><small>May <var>27<\/var>, <var>16:24<\/var> CEST<\/small>  <\/p>\n<p><strong>Update<\/strong> &#8211; Consumers in the EU can now login to Klarna at app.klarna.com. We will provide further updates regarding both other regions and our mobile apps in the near future.<br \/><small>May <var>27<\/var>, <var>16:15<\/var> CEST<\/small>  <\/p>\n<p><strong>Update<\/strong> &#8211; We are continuing to investigate issues with the Klarna consumer app. In the meantime, customers can still continue to make purchases using Klarna. We apologize for the disruption.<br \/><small>May <var>27<\/var>, <var>14:02<\/var> CEST<\/small>  <\/p>\n<p><strong>Update<\/strong> &#8211; We are currently experiencing system disturbances caused by a technical error. We are doing our utmost to return our system and services to full capacity and apologize for any inconvenience this is causing. While we are addressing the issue, customers are unable to log into the app.<br \/><small>May <var>27<\/var>, <var>12:01<\/var> CEST<\/small>  <\/p>\n<p><strong>Investigating<\/strong> &#8211; Technical teams are investigating the issue.<br \/><small>May <var>27<\/var>, <var>11:32<\/var> CEST<\/small><\/p>\n<\/blockquote>\n<p>After an app update, users noticed that they were suddenly shown the data and transactions of other users in the app. Numerous users complained about this behavior on Twitter.<\/p>\n<p><a href=\"https:\/\/twitter.com\/esraefe\/status\/1397842160607711232\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" title=\"Tweet about Klarna data breach\" alt=\"Tweet about Klarna data breach\" src=\"https:\/\/i.imgur.com\/Od2lm2G.png\"><\/a><\/p>\n<p>Anyone who logged out and back in multiple times was shown the data of different customers in each case. According to media reports, 90,000 users (around 0.1 percent of accounts) were affected. Klarna says its due to a \"human error\". This error was caused by an update applied at 10:50 a.m. and lasted 31 minutes, the company said. In the linked article on Golem, Klarna's statement is quoted thus:<\/p>\n<blockquote>\n<p>The error caused random user data to become visible to incorrect users when accessing our user interface. It is extremely important for us to emphasize that the access to the data was completely random and no card or bank data was displayed (encrypted data was visible). [&#8230;] <\/p>\n<p>In accordance with the GDPR standards, only non-sensitive data was disclosed. However, we recognize that what is considered non-sensitive is perceived very individually, and we always set our own standards higher than those of legal regulations such as the GDPR. <\/p>\n<\/blockquote>\n<p>Klarna writes that it was not possible to access the data of a specific user. Whether the whole thing was relevant under DSGVO or not should be judged by the data protection authorities &#8211; I mean, it is already DSGVO relevant if I can see the transaction data of third parties &#8211; even if it was random. And users also disagree with Klarna's representation. The company is a repeat offender, by the way, because during research I came across <a href=\"https:\/\/www.robin-data.io\/en\/data-protection-academy\/news\/data-breach-klarna-autofill\" target=\"_blank\" rel=\"noopener\">this article<\/a> from Feb. 2020. At the time, Klarna users noticed that entering their zip code and email address was enough to fill order forms with additional data. The forms are then automatically pre-filled with address data, or even date of birth or phone number. And in October 2020, data protection regulators launched an investigation because the company sent a newsletter to users without their consent, according to <a href=\"https:\/\/www.computerweekly.com\/news\/252490528\/Fintech-unicorn-Klarna-probed-over-data-misuse\" target=\"_blank\" rel=\"noopener\">the BBC<\/a>. <\/p>\n","protected":false},"excerpt":{"rendered":"<p>[German]I already know why I don't let financial service providers or fintechs access my bank accounts via app. According to media reports, Swedish payment service provider Klarna experienced a serious data protection breach. Users who used the Klarna app were &hellip; <a href=\"https:\/\/borncity.com\/win\/2021\/05\/27\/zahlungsdienstleister-klarna-fremde-konten-einsehbar\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[580],"tags":[69],"class_list":["post-20042","post","type-post","status-publish","format-standard","hentry","category-security","tag-security"],"_links":{"self":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/20042","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/comments?post=20042"}],"version-history":[{"count":0,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/posts\/20042\/revisions"}],"wp:attachment":[{"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/media?parent=20042"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/categories?post=20042"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/borncity.com\/win\/wp-json\/wp\/v2\/tags?post=20042"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}