Interbank confirms customer data breach after dark web listing
- Organization
- Interbank
- Exploit
- Hacking
- Industry
- Financial Services
Interbank, one of Peru's largest banks, acknowledged at the end of October 2024 that customer information had been exposed, after a post offering the data appeared on a dark web forum.
A threat actor using the handle kzoldyck advertised roughly 3.7 terabytes of files said to relate to about 3 million customers. The listing described names, national identity document numbers, dates of birth, phone numbers, email and home addresses, IP and device details, transaction records, payment card numbers with CVV codes and plaintext login credentials. The seller also claimed to hold credentials for internal bank systems.
The bank said that some data belonging to a group of clients had been exposed by a third party without its authorisation, and that it had immediately deployed additional security measures. Several online and mobile banking services were taken offline while the investigation ran, and customers reported problems changing passwords and completing transactions before access was restored.
The attacker told researchers that talks with Interbank had run for about two weeks before the bank ended them and declined to pay, after which the material was published. Interbank did not confirm the volume of records or comment on the extortion claim. It said customer deposits and financial products remained protected and advised account holders to monitor their statements as the investigation continued.