Meitav Trade Discloses Customer Data Exposure Through Vendor API Flaw
Published

Meitav Trade disclosed Tuesday that an interface operated by an external supplier exposed personal data of some customers after an incident detected on September 26. The company said an external actor used the interface to obtain affected accounts' full names, identity numbers, bank account numbers and beneficiary details where present. It said about 3,000 unsolicited one-time-code texts were sent to customer phone numbers, a count of messages rather than people, and attempts to change some recipient numbers failed. Meitav said it disabled the interface and that its investigation found no access to funds, trading accounts, trading systems, passwords or identity documents; it plans to notify affected customers.