Deutsche Bank customer data exposed in service provider's MOVEit breach
- Organization
- Deutsche Bank
- Exploit
- Third-Party Data Breach
- Industry
- Banking
Deutsche Bank confirmed in July 2023 that customer data had been exposed following a security incident at an external service provider that operates the bank's account switching service in Germany. German media identified the provider as Majorel, which was caught up in the exploitation of the MOVEit Transfer file transfer software.
The bank said its own systems were not affected at any point. The exposure was limited to customers in Germany who used the account switching service in 2016, 2017, 2018 and 2020, and to a single system running MOVEit in Germany. Reporting described the compromised fields as customer names and account numbers, or IBANs. The bank did not disclose how many customers were affected and said all of them had been contacted directly.
Deutsche Bank said the exposed data could not be used to gain access to accounts, but acknowledged that criminals could attempt to initiate unauthorized direct debits with it. In response the bank extended the period in which customers can dispute unauthorized debits to 13 months.
Other German institutions reported effects from the same provider incident. ING said a low four-figure number of customers who had used its account switching service were affected. Comdirect was indirectly affected and Deutsche Bank's Postbank arm reported limited impact, while Commerzbank said no customer data of its own was involved.