Belfius Bank Hit by KillSec Ransomware Attack

Incident Date: Sep 05, 2024

Attack Overview
VICTIM
Belfius Bank
INDUSTRY
Finance
LOCATION
Belgium
ATTACKER
Killsec
FIRST REPORTED
September 5, 2024

Ransomware Attack on Belfius Bank by KillSec

Belfius Bank, a prominent Belgian financial institution, has recently fallen victim to a ransomware attack orchestrated by the notorious group KillSec. This incident has raised significant concerns within the cybersecurity community, given Belfius's critical role in the Belgian financial sector.

About Belfius Bank

Established in 2011, Belfius Bank & Insurance serves over 3.8 million customers, including individuals, SMEs, large corporations, and public institutions. The bank operates through two main segments: Individuals and Entrepreneurs, Enterprises & Public (E&E&P). Belfius is known for its extensive digital transformation, boasting nearly 2 million active mobile banking users, and its commitment to sustainability and technological innovation.

Attack Overview

The ransomware attack was discovered on September 6, 2024, and involved the compromise of a third-party provider, Penbox, which stored data related to Belfius's SaaS enterprise clients. KillSec claims to have exfiltrated sensitive information, including customer names, addresses, and login details. Belfius has confirmed that their own systems remain uncompromised and that no sensitive customer information has been encrypted. The bank emphasized that the breach occurred through an external partner with whom they no longer maintain a working relationship.

About KillSec

KillSec, a ransomware group that emerged in 2021, is known for its sophisticated cybercriminal activities. The group has recently launched a Ransomware-as-a-Service (RaaS) platform, making advanced ransomware tools accessible to less skilled individuals. KillSec employs various tactics, including exploiting website vulnerabilities and credential theft, to gain access to systems and data. The group demands ransom payments in Monero (XMR), a privacy-focused cryptocurrency.

Penetration and Vulnerabilities

KillSec likely penetrated Belfius's systems through vulnerabilities in the third-party provider, Penbox. This incident underscores the risks associated with third-party vendors and the importance of stringent cybersecurity measures. Belfius's extensive digital infrastructure and reliance on external partners may have made it an attractive target for threat actors like KillSec.

Sources

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.