Belfius Bank Hit by KillSec Ransomware Attack
Incident Date:
September 5, 2024
Overview
Title
Belfius Bank Hit by KillSec Ransomware Attack
Victim
Belfius Bank
Attacker
Killsec
Location
First Reported
September 5, 2024
Ransomware Attack on Belfius Bank by KillSec
Belfius Bank, a prominent Belgian financial institution, has recently fallen victim to a ransomware attack orchestrated by the notorious group KillSec. This incident has raised significant concerns within the cybersecurity community, given Belfius's critical role in the Belgian financial sector.
About Belfius Bank
Established in 2011, Belfius Bank & Insurance serves over 3.8 million customers, including individuals, SMEs, large corporations, and public institutions. The bank operates through two main segments: Individuals and Entrepreneurs, Enterprises & Public (E&E&P). Belfius is known for its extensive digital transformation, boasting nearly 2 million active mobile banking users, and its commitment to sustainability and technological innovation.
Attack Overview
The ransomware attack was discovered on September 6, 2024, and involved the compromise of a third-party provider, Penbox, which stored data related to Belfius's SaaS enterprise clients. KillSec claims to have exfiltrated sensitive information, including customer names, addresses, and login details. Belfius has confirmed that their own systems remain uncompromised and that no sensitive customer information has been encrypted. The bank emphasized that the breach occurred through an external partner with whom they no longer maintain a working relationship.
About KillSec
KillSec, a ransomware group that emerged in 2021, is known for its sophisticated cybercriminal activities. The group has recently launched a Ransomware-as-a-Service (RaaS) platform, making advanced ransomware tools accessible to less skilled individuals. KillSec employs various tactics, including exploiting website vulnerabilities and credential theft, to gain access to systems and data. The group demands ransom payments in Monero (XMR), a privacy-focused cryptocurrency.
Penetration and Vulnerabilities
KillSec likely penetrated Belfius's systems through vulnerabilities in the third-party provider, Penbox. This incident underscores the risks associated with third-party vendors and the importance of stringent cybersecurity measures. Belfius's extensive digital infrastructure and reliance on external partners may have made it an attractive target for threat actors like KillSec.
Sources
Recent Ransomware Attacks
The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.
The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.