• Hey there! Welcome to TFC! View fewer ads on the website just by signing up on TF Community.

Serious Security Glitch in ICICI Bank's iMobile Alert

TechnoFino

Founder
TF Family
Founder
Admin
Several users have reported being able to view other customers' ICICI Bank credit cards on their iMobile app. Since the full card number, expiry date, and CVV are visible on iMobile, and one can manage international transaction settings, it's easy for someone to misuse another person's credit card for international transactions.

What can you do?
If you can't do anything, and someone has access to your card, they can change settings on iMobile without OTP or even MPIN. The best option is to block the card and replace it; this will provide some temporary relief.

Update:
It seems ICICI Bank has restricted access to credit card details on the iMobile app for everyone.

Update:
ICICI Bank response regarding the issue on mint
20240425_170314.jpg



Update 26/04/2024:
ICICI Bank has instructed its delivery partners to immediately return all in-transit debit and credit card deliveries to the bank.

@googley :

I have access to someone else’s Amazon Pay CC due to a security glitch on the iMobile app.
Although OTP restricts domestic transactions but I can do international transactions using the details from the iMobile app.
The app even allows me to enable international transactions in case it has been disabled by the actual user.

I have already flagged this to ICICI team they are working on this on priority as multiple customers have reported this. I wanted to alert the community folks too regarding the same.
 

Attachments

  • IMG_3721.jpeg
    IMG_3721.jpeg
    195 KB · Views: 480
  • IMG_3720.jpeg
    IMG_3720.jpeg
    196.7 KB · Views: 464
Last edited:

varun__goel_

TF Legend
I have access to someone else’s Amazon Pay CC due to a security glitch on the iMobile app.

Although OTP restricts domestic transactions but I can do international transactions using the details from the iMobile app.

The app even allows me to enable international transactions in case it has been disabled by the actual user.

I have already flagged this to ICICI team they are working on this on priority as multiple customers have reported this. I wanted to alert the community folks too regarding the same.
Please report this incident to RBI as well.

This is a big threat.
 

Transpointer

TF Premier
VIP Lounge
I have access to someone else’s Amazon Pay CC due to a security glitch on the iMobile app.

Although OTP restricts domestic transactions but I can do international transactions using the details from the iMobile app.

The app even allows me to enable international transactions in case it has been disabled by the actual user.

I have already flagged this to ICICI team they are working on this on priority as multiple customers have reported this. I wanted to alert the community folks too regarding the same.
What is their credit limit?
 

amit90

TF Premier
I noticed that ICICI cards transaction are successful, even if you put wrong 3 digit cvv. I complained about this issue, Bank took this casually but unfortunately i did not follow up due to busy schedule.. Did any member face this kind of issue?
 

sauravkumar

TF Premier
VIP Lounge
I have access to someone else’s Amazon Pay CC due to a security glitch on the iMobile app.

Although OTP restricts domestic transactions but I can do international transactions using the details from the iMobile app.

The app even allows me to enable international transactions in case it has been disabled by the actual user.

I have already flagged this to ICICI team they are working on this on priority as multiple customers have reported this. I wanted to alert the community folks too regarding the same.
Tagging our Doctor to fix it!!😂😂
@DocFixIt

Your expert advice please!!
 

varun__goel_

TF Legend
I noticed that ICICI cards transaction are successful, even if you put wrong 3 digit cvv. I complained about this issue, Bank took this casually but unfortunately i did not follow up due to busy schedule.. Did any member face this kind of issue?
Is the card tokenised where you used the card?
 
Top