However, rejecting the claims, Justdial said all the sensitive information of its users including financial information as well as any passwords are protected as per industry standards. The hyperlocal search platform also assured that the majority of the Justdial platform works on OTP-based authentication.
“The older versions of our apps, which currently cater to only a very small fraction of our users, were using certain APIs by which basis a particular mobile number entered, certain basic user details were accessible (no financial information was accessible). This vulnerability which existed on the older app platforms is also now fixed,” Justdial said in an official statement.
“Newer (current) versions of app where majority of users are available do not have the above vulnerability. We have implemented adequate encryption for the older APIs which were impacted and have initiated an independent tech-audit to identify any existing vulnerabilities,” the statement read further.
According to Rajaharia, the data breach happened via an older version on Justdial’s website which has not been tended to since mid-2015.
Founded by VSS Mani in 1996, Justdial has a database of approximately 22.7 million listings and 452,900 active paid campaigns, as of 30 June 2018