Welcome Guest ( Log In | Register )

Outline · [ Standard ] · Linear+

 Grabpay unauthorized transaction, financial fraud

views
     
silverhawk
post Jan 24 2023, 11:44 AM

Eyes on Target
Group Icon
Elite
4,956 posts

Joined: Jan 2003


QUOTE(vexus @ Jan 24 2023, 02:24 AM)
this will include tng ewallet, shopeepay, boost, lazada ? Every local apps payment gateway is at risk now. Backdoor Loophole is either at Revenue side or thier outsourced partner PayerMax https://www.payermax.com/about/
https://www.revenue.com.my/partners/

https://www.revenue.com.my/revpay/

https://www.revenue.com.my/about/
*
Likely got issue on 2 sides

1) Grab - How could revenue harvest log into user account?

2) Revenue Harvest - This is where likely someone in the company that has access to api keys or customer data logged into the victims account to initiate the transfer.

I'm not surprised if revenue harvest outsourced some of their work to indonesia, which is quite a common practice.
silverhawk
post Jan 27 2023, 10:29 AM

Eyes on Target
Group Icon
Elite
4,956 posts

Joined: Jan 2003


QUOTE(Szzz @ Jan 26 2023, 06:32 PM)
I'm not well versed with Grab API but if its similar to payment gateways, I don't see how Revenue Harvest can even get customer payment tokens without them logging into customer's Grab account.
*
I'm not too sure as well, but the pattern suggests it. Since not everyone's facing the problem, just a handful of people and revenue harvest is the common denominator. My guess would be the token being captured somehow by a POS/Terminal that the customer use grabpay to pay with. Websites "should" redirect to grab's servers so no token exchange in the process.

Would be a huge security flaw to allow tokens to be captured by 3rd party and for it not to be a single-use token. Grab has some accountability here as well.

 

Change to:
| Lo-Fi Version
0.0191sec    0.84    6 queries    GZIP Disabled
Time is now: 14th December 2025 - 03:39 PM