Akchabarsearch
    Kyrgyz banks lack cybersecurity: every second website is vulnerable to hacking
    Image source: DALL·E

    Published

    07/03/2025, 11:51

    Kyrgyz banks lack cybersecurity: every second website is vulnerable to hacking

    According to a study conducted by the Digital Resilience Association (DRA) in collaboration with TSARKA Kyrgyzstan, nearly half of the websites of the country’s banks and microfinance institutions exhibit low level of vulnerability. Out of 26 resources examined, 14 were found to have critical vulnerabilities that could be exploited for data theft and attacks on clients.

    The study revealed a wide range of issues: from open ports and outdated TLS versions to vulnerable subdomains and misconfigured mail servers. The average security score was 71.75%. For the financial sector, where billions of soms and public trust are at stake,  this is an unsatisfactory result.

    Among the identified vulnerabilities were the absence of basic security headers (such as X-XSS-Protection, Content-Security-Policy, etc.), outdated CMS platforms, access to critical paths like /admin or /config.bak, and a lack of protection against DNS spoofing. Not a single website uses DNSSEC — an international standard that ensures the integrity and authenticity of DNS data.

    It was also found that 9 websites still use the outdated TLS 1.2 protocol, despite the availability of more secure versions. Critical CVEs — officially registered vulnerabilities in international databases — were detected on 10 platforms. For example, CVE-2023-40743 or CVE-2021-27023 could lead to complete traffic interception and server compromise.

    The best performance was demonstrated by the websites obank.kg, fincabank.kg, esb.kg, kicb.net, and ab.kg — their security levels were assessed at over 85%.

    “The results of the cybersecurity analysis of Kyrgyzstan's banking sector indicate a trend toward improving information security; however, several web resources were found to have serious vulnerabilities that need to be addressed as soon as possible,” — the study’s authors note. — The main vulnerabilities include misconfigured DNS settings, lack of basic protection against phishing and spoofing, open ports and directories, as well as outdated technologies with known vulnerabilities. Some online resources remain at a minimal level of protection, despite their public significance and the potential risks of data leaks or system compromise.”

    Among the recommendations are the mandatory implementation of SPF, DKIM and DMARC on all domains; auditing subdomains and eliminating forgotten test resources; closing non-standard ports; updating CMS platforms and web application components; and installing automated vulnerability monitoring systems.

    The importance of appointing cybersecurity officers at the executive level of banks is particularly emphasized, along with the implementation of secure email protocols and regular training for IT specialists.

    Experts are confident that this approach can protect the banking system from scenarios where a single configuration error could lead to significant losses. Moreover, it is not only about cybersecurity threats but also about the bank's reputation.


    Read Similar

    • Stories instead of visas: How travel bloggers opened Kyrgyzstan and Uzbekistan to each other

      Over the past few years, Kyrgyzstan and Uzbekistan have unexpectedly become each other’s top tourist markets. Open borders, shared cultural heritage, and the absence of a language barrier have made cross-border tourism not only convenient but also trendy.
      7/8/2025, 6:22:47 AM
    • Housing prices have dropped in the city center but increased in Energetikov town and Tunguch

      In April 2025, Bishkek recorded an increase in the average price per square meter of apartments in standard series (104, 105, 308 series, as well as individual-type apartments) compared to March. According to the data, the price rose from 119 thousand to 130 thousand KGS per square meter. This is an 8.98% increase in a month, which is significant for the capital's real estate market. These figures
      5/28/2025, 11:36:37 AM
    • In 2025, you won't get anywhere without knowing Kyrgyz. How much does it cost to learn the language?

      From 2025, new rules regarding knowledge of the state language will come into force in Kyrgyzstan. These changes will affect a wide range of professionals, from civil servants to medical workers. Let's take a look at what exactly will change, how to prepare for the new requirements, and what opportunities knowledge of the Kyrgyz language opens up in the professional sphere.
      5/14/2025, 11:26:36 AM
    • Where can I barbecue during the May holidays?

      In Ala-Archa National Park, grilling kebabs and open fires have been banned since May. This measure was introduced for fire safety and to preserve the ecosystem. The ban is particularly strict in spring and summer, when the risk of forest fires is high. Violators may be fined and, in some cases, brought to administrative responsibility.
      5/1/2025, 11:28:46 AM