BianLian emailed Sable International customers after immigration firm breach
- Organization
- Sable International
- Exploit
- Hacking
- Industry
- Immigration Services
Sable International, a firm providing immigration, citizenship and financial services with operations in the United Kingdom, South Africa and Australia, confirmed on August 2, 2024 that it had been hit by what it described as a sophisticated criminal cyberattack.
The company took its servers, website and transactional portals offline as a precaution while it responded. It said an internal investigation had established that a limited number of clients had personal data taken, and that work to determine the full extent was continuing. Chief executive Reg Bamford said the company was devastated by the incident.
The BianLian extortion group claimed responsibility earlier that week. Rather than pressing the firm alone, the attackers emailed Sable International's customers directly about the stolen data, a tactic intended to push the company toward paying. Sable International urged clients not to reply to those messages, told them to contact the firm instead, and set up a team to handle enquiries.
The breach was reported to regulatory and law enforcement authorities in South Africa, where notification is required under the Protection of Personal Information Act, and in the United Kingdom. BianLian has been the subject of joint advisories from the FBI, CISA and the Australian Cyber Security Centre covering attacks on critical infrastructure since June 2022, and was behind the 2023 breach of Save the Children International. The company's website remained offline as of that Friday afternoon.