Santander says third-party database breach hit customers and staff

Organization
Banco Santander
Exploit
Third-Party Data Breach
Industry
Banking

Banco Santander said on 14 May 2024 that it had detected unauthorized access to a database containing bank information that was hosted by a third-party provider. The Spanish group said the records covered customers of Santander Chile, Santander Spain and Santander Uruguay, together with all current and some former Santander employees.

The bank said customer data in its other markets and businesses was not involved. It also said the database held no transactional data and no credentials that would allow transactions on accounts, including online banking details and passwords, and that its own operations and systems were unaffected so customers could continue to transact normally.

Santander said it blocked the compromised access as soon as it was identified, introduced additional fraud prevention controls, and notified regulators and law enforcement. It said it was contacting affected customers and employees directly.

The bank did not disclose how many people were affected, which provider hosted the database, or precisely which categories of personal data were exposed. SecurityWeek noted that Santander's use of the phrase "unauthorized access" left open whether the incident involved criminal activity or a researcher discovering an internet-exposed system. No figure for the number of records involved had been published as of the disclosure.

Sources