Attempted Breach of Meitav Trade: The Company’s Responsibility and the Risks to Customers
An attempt to access thousands of Meitav Trade accounts was blocked, but personal information belonging to certain customers was extracted. The Privacy Protection Authority has opened an examination of the company’s and the external provider’s compliance with statutory requirements and the Information Security Regulations.
Key facts
- •Approximately 3,000 text messages containing verification codes
- •A vulnerability was discovered in an external provider’s API interface
- •Information belonging to certain customers was exposed
- •According to Meitav, the funds, passwords and trading accounts were not compromised
- •Amendment No. 13 to the Privacy Protection Law applies
- •The Privacy Protection Authority opened a supervisory examination
What Happened
On Saturday, Meitav Trade customers began receiving text messages containing one-time verification codes, even though they had not requested them. An examination uncovered a vulnerability in one of an external provider’s API interfaces: approximately 3,000 messages were sent during the attack, and several unsuccessful attempts were made to change the telephone number used to receive the code. Access to the interface was blocked immediately, and its use was discontinued. The trading systems continued to operate as usual.
What Information Was Exposed
The full name, identity card number, bank account number and beneficiary details, if provided, were extracted for certain customers. According to Meitav, the attackers did not gain access to funds, trading accounts and systems, passwords, financial data or identification documents. The company said it would notify customers whose personal information was extracted.
The Company’s Responsibility
Financial information may be considered highly sensitive information. Under Amendment No. 13 to the Privacy Protection Law, the owner of a database must act to stop the violation, even if the vulnerability originated with an external provider—the database holder. Meitav said it had contacted the Israel National Cyber Directorate and the Privacy Protection Authority; the latter opened a supervisory examination regarding the company’s and the provider’s compliance with statutory and regulatory requirements. The mere occurrence of a cyber incident does not yet indicate a violation: the protective measures taken, access permissions, oversight of external providers and actions taken after the attack was discovered are being examined.
Possible Consequences
Failure to submit a required notification to the Privacy Protection Authority may result in a financial sanction—ranging from tens of thousands to hundreds of thousands of shekels, depending on the database’s security level. Amendment No. 13 expanded the Authority’s powers to supervise, investigate and impose significant sanctions for violations of the Information Security Regulations. The source does not report that any fine was imposed on Meitav or the provider.
Risks to Customers
The exposed information could be used for phishing, impersonation and targeted fraud, even if account activity was not disrupted. Particular caution should be exercised regarding unexpected messages and requests to provide a verification code or additional details. Accessing an account through links in text messages or emails also creates a risk.
What this means for you
Customers in a similar situation should bear in mind that technically stopping the attack does not rule out the later use of information that has already been exposed. After receiving notification of the incident, it is advisable to carefully check exactly which details were compromised and to treat unexpected communications made in the financial institution’s name with suspicion. At the same time, the company remains responsible for organizing access controls and overseeing external providers.
Find a lawyer for this topic
- Lawyers: Права потребителя
- Lawyers in Тель-Авив
- Lawyers in Иерусалим
- Lawyers in Хайфа
- Lawyers in Ришон ле-Цион