Truist Bank confirms October 2023 breach after employee data listed for sale
- Organization
- Truist Bank
- Exploit
- Hacking
- Industry
- Banking
Truist Bank, one of the ten largest US commercial banks, confirmed in June 2024 that it had suffered a cybersecurity incident in October 2023, after data said to have come from the bank appeared for sale on a criminal forum.
A threat actor using the handle Sp1d3r advertised the material on BreachForums on 12 June 2024 for $1 million. The listing claimed to hold records for about 65,000 employees, along with bank transaction data showing names, account numbers and balances, and source code for the bank's interactive voice response system used for funds transfers. Those claims were the seller's and were not independently verified.
Truist said the 2023 incident had been quickly contained, and that it had investigated with outside security consultants and law enforcement, taken additional steps to secure its systems and notified a small number of clients at the time. The bank said it had found no indication of fraud arising from the incident and had made identity protection services available at no cost. It also rejected suggestions of any connection to the Snowflake credential-theft campaign then under way, saying it had found no evidence of a Snowflake incident at the company.
A proposed class action filed in the US District Court for the Western District of North Carolina on 21 June 2024 put the attack date at 27 October 2023 and alleged that some customers did not receive notification letters until May 2024.