Evolve Bank, a financial institution headquartered in Arkansas, was the victim of an attack by the LockBit ransomware group which resulted in a data leak onto the Dark Web this week.
LockBit had drawn attention to itself earlier this week after claiming to have hacked the US Federal Reserve.
The statement noted the company had contacted law enforcement authorities as part of the bank's investigation and response efforts.
The company added that retail banking customers' debit cards, online, and digital banking credentials did not seem to be affected by the breach.
Evolve Already Target of Fed Action Earlier this month, the Federal Reserve Board issued an enforcement action against Evolve Bancorp and Evolve Bank & Trust, accusing the company of deficiencies in their anti-money laundering, risk management, and consumer compliance programs.
Ai, said in an emailed statement that once an organization experiences a breach, and the smoke begins to clear, the biggest decision is what to do next.
That means that teams must find the attack path that allowed the breach to happen, and they need to uncover other attack paths that could enable it to happen again.
Financial Sector Defenses Must Evolve Piyush Pandey, CEO at Pathlock, says the recent enforcement action against Evolve Bancorp underscores the critical importance of robust sensitive data and application access controls within financial institutions.
He also points out that the interconnectedness and complexity of supply chains in the financial sector increases the difficulty of managing and securing third-party access.
He adds that by focusing on rigorous controls testing and enforcement, including stringent management of third-party identities and access, financial institutions can significantly strengthen their security posture, protect sensitive data, and ensure compliance with regulatory requirements.
Narayana Pappu, CEO at Zendata, notes that financial and medical institutions store significant amount highly sensitive data with significant monetary impact for exposed organizations.
From his perspective, data minimization - not capturing or storing data that is not needed - would help these institutions significantly.
This Cyber News was published on www.darkreading.com. Publication date: Fri, 28 Jun 2024 15:10:08 +0000