Skip to main content

Meitav Trade Discloses Customer Data Exposure Through Vendor API Flaw

Courtroom-sketch editorial illustration of an archival server aisle; contextual data infrastructure, not Meitav Trade's systems or the reported exposure.

Meitav Trade disclosed Tuesday that an interface operated by an external supplier exposed personal data of some customers after an incident detected on September 26. The company said an external actor used the interface to obtain affected accounts' full names, identity numbers, bank account numbers and beneficiary details where present. It said about 3,000 unsolicited one-time-code texts were sent to customer phone numbers, a count of messages rather than people, and attempts to change some recipient numbers failed. Meitav said it disabled the interface and that its investigation found no access to funds, trading accounts, trading systems, passwords or identity documents; it plans to notify affected customers.

Sources

Meitav Trade InvestmentsSource Language: HebrewOpens in a new tab.

Something went wrong

We couldn't complete that action. Check your connection and try again.