Daily Dark Web
  • Home
  • Data Breaches
  • Inside the Adversary
    • Dark Web Informants
  • DDW Top Lists
  • Ransomware News
  • DarkWeb News
    • Vulnerability
    • Cyber Attacks
  • Unauthorized Accesses
  • About Us
No Result
View All Result
  • Home
  • Data Breaches
  • Inside the Adversary
    • Dark Web Informants
  • DDW Top Lists
  • Ransomware News
  • DarkWeb News
    • Vulnerability
    • Cyber Attacks
  • Unauthorized Accesses
  • About Us
No Result
View All Result
Daily Dark Web
No Result
View All Result
Home DarkWeb News & Services

Alleged IDOR Vulnerability in Al Rajhi Bank’s APIs for Sale

September 29, 2024
Reading Time: 1 min read
Alleged IDOR Vulnerability in Al Rajhi Bank’s APIs for Sale

A threat actor claims to have found an IDOR (Insecure Direct Object Reference) vulnerability in Al Rajhi Bank’s APIs. The individual allegedly discovered the flaw through fuzzing, which allows unauthorized access to user shopping carts and possibly other sensitive data.

The threat actor is selling this alleged vulnerability for $69 in Bitcoin. They suggest that with some reconnaissance, further exploitation could reveal more critical flaws, such as a possible NoSQL injection.

Although the claim remains unverified, the sale raises concerns about the growing black market for banking exploits. It also underlines the need for financial institutions to strengthen their security measures in an increasingly digital world.

The bank is a major investor in Saudi Arabia’s business and is one of the largest joint stock companies in the Kingdom, with over SR 330.5 billion in AUM ($88 billion) and over 600 branches. Its head office is located in Riyadh, with six regional offices. Al Rajhi Bank also has branches in Kuwait and Jordan, and a subsidiary in Malaysia and Syria.

 

Tags: Al Rajhi BankBankingFinancecIDORNoSQL
ShareTweet

Related Posts

Abu Dhabi Department of Finance Super Admin Access Sale
Unauthorized Accesses

Abu Dhabi Department of Finance Super Admin Access Sale

April 27, 2026
BreachForums Announces VECT Partnership and Security Updates
DarkWeb News & Services

BreachForums Announces VECT Partnership and Security Updates

April 16, 2026
Threat Actor Selling Root Access to Mexican Manufacturing Firm
Unauthorized Accesses

Threat Actor Selling Root Access to Mexican Manufacturing Firm

April 3, 2026
Hualun New Materials Suffers Massive Data Breach by SnowSoul
Unauthorized Accesses

Peak Neuro Investigating Alleged Admin Panel Access Sale

March 16, 2026
GlobalNet Data Breach: Tunisian ISP Compromised
Data Breaches

GlobalNet Data Breach: Tunisian ISP Compromised

March 11, 2026
ShinyHunters Telegram Update Claims Second Leader Arrested
DarkWeb News & Services

ShinyHunters Telegram Update Claims Second Leader Arrested

February 5, 2026
Next Post
Alleged Data Breach Exposes Over 128,000 Mobility Compare Customers

Alleged Data Breach Exposes Over 128,000 Mobility Compare Customers

digiDirect’s Customer Information Allegedly Leaked on Dark Web

digiDirect's Customer Information Allegedly Leaked on Dark Web

Recommended Stories

ICBSCAC Data Breach Hits Malaysian Methodist Church Website

ICBSCAC Data Breach Hits Malaysian Methodist Church Website

November 17, 2025
UUSLOT Gambling Website Data Breach Exposes Player Data

UUSLOT Gambling Website Data Breach Exposes Player Data

October 7, 2025
TBN Israel Allegedly Hacked by Handala Hacking Group

TBN Israel Allegedly Hacked by Handala Hacking Group

June 16, 2025

Popular Stories

  • SudamericaData Breach Exposes Over 1TB of Argentine Records

    SudamericaData Breach Exposes Over 1TB of Argentine Records

    0 shares
    Share 0 Tweet 0
  • Threat Actor Claims Sale of Dell Database Containing 49 Million Customer Records

    0 shares
    Share 0 Tweet 0
  • SUUMO, CHINTAI, At Home, HOME’S Suffer Data Breach

    0 shares
    Share 0 Tweet 0
  • Financial Tech Giant SilverLake Axis Allegedly Breached – 423GB of Data for Sale

    0 shares
    Share 0 Tweet 0
  • Telekom Serbia Investigates Leak of 160,000 Customer Records

    0 shares
    Share 0 Tweet 0
Daily Dark Web

Disclaimer: Daily Dark Web (DDW) is an independent media platform providing information, analysis, and reporting on cybersecurity, cyber incidents, and related digital developments. All content published on this website is for informational and journalistic purposes only. DDW does not support, endorse, or promote any illegal activities, threat actors, or organizations referenced in its content. Any statements, claims, or opinions expressed by third parties, including interview subjects, are their own and do not reflect the views of DDW. Such content may include unverified information and should be interpreted critically. DDW does not participate in, facilitate, or coordinate any activities discussed or referenced on this platform. Under no circumstances should any content be interpreted as encouragement, instruction, or endorsement of unlawful actions. All interactions and publications are conducted in the public interest to enhance awareness and understanding of the evolving cyber landscape.

No Result
View All Result
  • About Us
  • Home
  • Newsletter
  • Privacy Policy

Disclaimer: Daily Dark Web (DDW) is an independent media platform providing information, analysis, and reporting on cybersecurity, cyber incidents, and related digital developments. All content published on this website is for informational and journalistic purposes only. DDW does not support, endorse, or promote any illegal activities, threat actors, or organizations referenced in its content. Any statements, claims, or opinions expressed by third parties, including interview subjects, are their own and do not reflect the views of DDW. Such content may include unverified information and should be interpreted critically. DDW does not participate in, facilitate, or coordinate any activities discussed or referenced on this platform. Under no circumstances should any content be interpreted as encouragement, instruction, or endorsement of unlawful actions. All interactions and publications are conducted in the public interest to enhance awareness and understanding of the evolving cyber landscape.

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?