Western Alliance Bank notifies 21,899 customers after Cleo file transfer breach

Organization
Western Alliance Bank
Exploit
Third-Party Data Breach
Industry
Financial Services

Western Alliance Bank, a Phoenix-based lender holding more than $80 billion in assets, began notifying 21,899 people in March 2025 that their personal information had been stolen through an attack on a third-party file transfer product.

The bank said an unauthorized party exploited a previously unknown flaw in a vendor's secure file transfer software and copied files between October 12 and October 24, 2024. The vendor disclosed the vulnerability on October 27, 2024, but Western Alliance did not confirm that its own data had been taken until January 27, 2025, and completed its review of the affected files on February 21. The bank first referenced the incident in a February filing with the Securities and Exchange Commission.

The stolen records included names and Social Security numbers and, for some customers, dates of birth, financial account numbers, driver's license numbers, tax identification numbers and passport details.

Reporting linked the intrusion to the Clop extortion group's campaign against Cleo's LexiCom, VLTransfer and Harmony products, which exploited CVE-2024-50623 and a second flaw, CVE-2024-55956, to deploy a Java backdoor researchers named Malichus. Clop added Western Alliance to its leak site in January 2025 alongside dozens of other named victims.

Western Alliance offered affected individuals one year of complimentary identity protection services and filed breach notices with state regulators, including the attorneys general of Maine and California.

Sources