everest attacks Feedbank Financial Services ltd

Incident Date:

September 26, 2022

World map

Overview

Title

everest attacks Feedbank Financial Services ltd

Victim

Feedbank Financial Services ltd

Attacker

Everest

Location

Ludhiana, India

Punjab, India

First Reported

September 26, 2022

Everest Ransomware Attacks Fedfina Financial Services Ltd.

Everest, a ransomware group, has claimed responsibility for an attack on Fedfina Financial Services Ltd., a subsidiary of Federal Bank. The victim's website is located at their official domain. Fedfina operates in the finance sector and is based in India, with over 460 branches across the country. The company offers a variety of financial products, including gold, home, car, and business loans, as well as loans against property.

The ransomware attack resulted in the leak of sensitive personally identifiable information (PII) of approximately 600,000 customers. This data includes names, ages, phone numbers, driving license details, voter IDs, passport numbers, and more. The data was allegedly sold on a cybercriminal forum, with the vendor claiming to have photographic copies of identification cards.

While specific vulnerabilities exploited in the attack on Fedfina are not detailed, the company's significant presence and the sensitive nature of the financial data it processes evidently make it a prime target for cybercriminals. This incident highlights the critical need for robust cybersecurity measures, such as regular vulnerability scanning, network segmentation, and employee security awareness training, to safeguard against such threats.

The Everest ransomware attack on Fedfina Financial Services Ltd. serves as a stark reminder of the importance of stringent cybersecurity practices within the financial sector. It is imperative for companies to maintain vigilance against cyber threats and implement comprehensive security measures to protect sensitive data and prevent data breaches.

Sources

Recent Ransomware Attacks

The Recent Ransomware Attacks (RRA) site acts as a watchtower, providing you with near real-time ransomware tracking of attacks, groups and their victims. Given threat actors’ overarching, lucrative success so far, ransomware attacks have become the most ubiquitous, and financially and informationally impactful cyber threat to businesses and organizations today.

The site’s data is generated based on hosting choices of real-world threat actors, and a handful of other trackers. While sanitization efforts have been taken, we cannot guarantee 100% accuracy of the data. Attack updates will be made as source data is reported by reputable sources. By viewing, accessing, or using RRA you acknowledge you are doing so at your own risk.