Belfius Bank Hit by KillSec Ransomware Attack
Ransomware Attack on Belfius Bank by KillSec
Belfius Bank, a prominent Belgian financial institution, has recently fallen victim to a ransomware attack orchestrated by the notorious group KillSec. This incident has raised significant concerns within the cybersecurity community, given Belfius's critical role in the Belgian financial sector.
About Belfius Bank
Established in 2011, Belfius Bank & Insurance serves over 3.8 million customers, including individuals, SMEs, large corporations, and public institutions. The bank operates through two main segments: Individuals and Entrepreneurs, Enterprises & Public (E&E&P). Belfius is known for its extensive digital transformation, boasting nearly 2 million active mobile banking users, and its commitment to sustainability and technological innovation.
Attack Overview
The ransomware attack was discovered on September 6, 2024, and involved the compromise of a third-party provider, Penbox, which stored data related to Belfius's SaaS enterprise clients. KillSec claims to have exfiltrated sensitive information, including customer names, addresses, and login details. Belfius has confirmed that their own systems remain uncompromised and that no sensitive customer information has been encrypted. The bank emphasized that the breach occurred through an external partner with whom they no longer maintain a working relationship.
About KillSec
KillSec, a ransomware group that emerged in 2021, is known for its sophisticated cybercriminal activities. The group has recently launched a Ransomware-as-a-Service (RaaS) platform, making advanced ransomware tools accessible to less skilled individuals. KillSec employs various tactics, including exploiting website vulnerabilities and credential theft, to gain access to systems and data. The group demands ransom payments in Monero (XMR), a privacy-focused cryptocurrency.
Penetration and Vulnerabilities
KillSec likely penetrated Belfius's systems through vulnerabilities in the third-party provider, Penbox. This incident underscores the risks associated with third-party vendors and the importance of stringent cybersecurity measures. Belfius's extensive digital infrastructure and reliance on external partners may have made it an attractive target for threat actors like KillSec.
Sources
See Halcyon in action
Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!