/security

News and resources on cyber and physical threats to banks and fintechs worldwide.

Klarna app bug logged people into other users' accounts

Klarna was forced to temporarily shut down its app yesterday after a "self-inflicted incident" saw some users logged in to other people's accounts, giving them access to personal information.

  5 Be the first to comment

Klarna app bug logged people into other users' accounts

Editorial

This content has been selected, created and edited by the Finextra editorial team based upon its relevance and interest to our community.

In a statement, Klarna says that a human error made during an app update caused a bug that meant that for 31 minutes up to 9500 users saw their personal data compromised.

The Swedish buy now, pay later unicorn says that card and bank details were not shown and that the visible information would be classified as "non-sensitive" under GDPR.

However, one London-based customer reported on Twitter: "I was able to see users’ partial card details under the “Payment Methods” section including bank names and mandate reference IDs. I was also able to remove stored card details and / or add new card details.

The Tweeter says she saw the details of "more than 20 random users," and had access to phone numbers and purchase histories.

Sponsored [Webinar] SaaS savvy: Preparing for embedded and data driven bank payments

Related Company

Comments: (0)

Preventing disaster: How banks can address operational resilience to prepare for global outagesFinextra Promoted[On-Demand Webinar] Preventing disaster: How banks can address operational resilience to prepare for global outages