[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$ft3RCGdIYHcYshZF8VkyXUr6d7e6ybJnBx4LdRBv1POY":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":17,"created_at":18,"published_at":19,"article":20,"tags":24,"podcasts":37},"5e3a6aae-fa98-428b-8d1b-7dd64b42b749","hsbc-india-stores-customer-passwords-in-plaintext","dc978657-0d9c-4efc-bb6a-8fe62423ae2d","HSBC India Stores Customer Passwords in Plaintext","HSBC India was found storing customer credentials in plaintext instead of using cryptographic hashes, representing a fundamental violation of password security best practices. This means bank employees and systems have direct access to customer passwords, creating massive security and privacy risks. Proper password hashing should make it technically impossible for anyone, including system administrators, to view actual passwords. This critical failure at a major financial institution exposes millions of customers to potential credential theft and unauthorized access to their banking accounts.","**Immediate actions:**\n- Audit all systems storing user credentials to verify proper hashing implementation\n- Force immediate password reset for all affected customer accounts\n- Implement emergency access restrictions to credential databases\n\n**Long-term improvements:**\n- Deploy industry-standard password hashing algorithms like bcrypt or Argon2\n- Establish mandatory code reviews for all authentication-related changes\n- Implement privileged access management for systems handling sensitive data\n\n**Detection measures:**\n- Set up automated monitoring to detect plaintext credential storage\n- Conduct regular penetration testing focused on authentication mechanisms\n- Implement data loss prevention tools to identify credential exposures",[12,13,14,15,16],"CIS Control 6.2","NIST SP 800-63B","PCI DSS 8.2.1","ISO 27001 A.9.4.3","GDPR Article 32","published","2026-03-31T19:07:28.63256+00:00","2026-03-31T19:07:28.532+00:00",{"id":7,"url":21,"slug":22,"title":23},"https:\u002F\u002Fx.com\u002Fvxunderground\u002Fstatus\u002F2039048864217416035","1-this-isn-t-fake-2-credentials-are-stored-as-hashes-it-should-be-literally-with","1. This isn't fake.\n\n2. Credentials are stored as hashes. It should be literally, with no exagger...",[25,31],{"id":26,"name":27,"slug":28,"description":29,"color":30},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":32,"name":33,"slug":34,"description":35,"color":36},"c8b843a5-d5a7-41d1-8d3b-cabded09d2ef","Data Protection","data-protection","Unencrypted data, missing DLP, poor classification","#3b82f6",[]]