Data Misuse

Threats relating to the mishandling of sensitive customer data

Affected entity: MNO

Risk: Unauthorized access to user data and interception of data in transit.

  • Vulnerability: Weak encryption practices or sending sensitive information in clear text over insecure traffic channels like SMS and USSD (SD: communication security)

Affected entity: DFS Provider and Third-party providers

Risk: Exposure of Sensitive data

  • Vulnerability: Inadequate data protection controls (SD: privacy)

Risk: Exposure of customer sensitive information during transactions or through APIs (SD: privacy)

  • Control 5.3: DFS providers should restrict the sharing of information to be only the minimum amount required for transactions with third parties and service providers

  • Vulnerability: Weak encryption on the API interfaces (SD: privacy)

Last updated