ALPHV claimed 5TB of data from ATM installer Quality Service Installation

Organization
Quality Service Installation (QSI), Inc.
Exploit
Ransomware
Industry
Banking Technology

The ALPHV ransomware operation, also tracked as BlackCat, added Quality Service Installation to its extortion site on October 14, 2023. QSI installs and services automated teller machines and interactive teller machines for banks and credit unions across the United States and is among the larger resellers of NCR banking equipment.

The group claimed it had taken financial records, client files, personal data and product and development material, and said the haul included roughly 5TB of SQL database content. Its listing named about ten financial institutions whose information it said was caught up in the theft, among them Wesbanco, First Financial Bank, Stock Yards Bank and Trust, German American Bank and SECU of Maryland. QSI did not publicly confirm the leak site claims, and both The Cyber Express and teiss reported the figures as unverified.

The compromise itself predated the extortion post. In late September 2023 a cybersecurity alert about an intrusion at QSI circulated through the credit union sector, and trade bodies passed it to members with instructions to check their exposure, activate incident response teams and prepare member communications.

A follow-up NCUA cybersecurity alert in early October 2023 told credit unions that QSI had contained the compromise, that some ITMs and ATMs had been shut down for remediation, and that QSI was working with the FBI's Cyber Division to analyze log files and share indicators of compromise. The alert said QSI had no indication at that time that any customer data was compromised, and that NCR's networks and processing systems were operating normally with no impact on NCR direct customers.

Sources