Ransomware at C-Edge Technologies knocked roughly 300 Indian banks offline
- Organization
- C-Edge Technologies
- Exploit
- Ransomware
- Industry
- Financial Services
The National Payments Corporation of India (NPCI) disclosed on July 31, 2024 that C-Edge Technologies, a technology services provider used by India's smaller banks, had been hit by a ransomware attack. NPCI said it had temporarily isolated C-Edge from the country's retail payment systems while the incident was assessed.
C-Edge is a joint venture between the State Bank of India and Tata Consultancy Services, and supplies core banking and payment infrastructure to cooperative banks and regional rural banks. The isolation left customers of roughly 300 of those institutions unable to complete ATM withdrawals or UPI transfers. The affected banks accounted for about 0.5 percent of India's total retail payment volumes.
According to CSO Online, the intrusion reached C-Edge through Brontoo Technology Solutions, a third party that works with the firm, and involved a misconfigured Jenkins server exposed to CVE-2024-23897. Reporting named the RansomEXX group, operating as RansomEXX v2.0, as the operator behind the attack, with the gang claiming to have taken data from a connected payment platform.
An independent forensic auditor reviewed the environment and concluded that the impact was confined to C-Edge systems hosted in its own data centre rather than the infrastructure of the cooperative or regional rural banks. NPCI restored connectivity on August 1, 2024, and the affected banks resumed normal customer services.