Belfius Bank Hit by KillSec Ransomware Attack

Incident Date:

September 5, 2024

World map

Overview

Title

Belfius Bank Hit by KillSec Ransomware Attack

Victim

Belfius Bank

Attacker

Killsec

Location

Bruxelles, Belgium

, Belgium

First Reported

September 5, 2024

Ransomware Attack on Belfius Bank by KillSec

Belfius Bank, a prominent Belgian financial institution, has recently fallen victim to a ransomware attack orchestrated by the notorious group KillSec. This incident has raised significant concerns within the cybersecurity community, given Belfius's critical role in the Belgian financial sector.

About Belfius Bank

Established in 2011, Belfius Bank & Insurance serves over 3.8 million customers, including individuals, SMEs, large corporations, and public institutions. The bank operates through two main segments: Individuals and Entrepreneurs, Enterprises & Public (E&E&P). Belfius is known for its extensive digital transformation, boasting nearly 2 million active mobile banking users, and its commitment to sustainability and technological innovation.

Attack Overview

The ransomware attack was discovered on September 6, 2024, and involved the compromise of a third-party provider, Penbox, which stored data related to Belfius's SaaS enterprise clients. KillSec claims to have exfiltrated sensitive information, including customer names, addresses, and login details. Belfius has confirmed that their own systems remain uncompromised and that no sensitive customer information has been encrypted. The bank emphasized that the breach occurred through an external partner with whom they no longer maintain a working relationship.

About KillSec

KillSec, a ransomware group that emerged in 2021, is known for its sophisticated cybercriminal activities. The group has recently launched a Ransomware-as-a-Service (RaaS) platform, making advanced ransomware tools accessible to less skilled individuals. KillSec employs various tactics, including exploiting website vulnerabilities and credential theft, to gain access to systems and data. The group demands ransom payments in Monero (XMR), a privacy-focused cryptocurrency.

Penetration and Vulnerabilities

KillSec likely penetrated Belfius's systems through vulnerabilities in the third-party provider, Penbox. This incident underscores the risks associated with third-party vendors and the importance of stringent cybersecurity measures. Belfius's extensive digital infrastructure and reliance on external partners may have made it an attractive target for threat actors like KillSec.

Sources

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.