Rupicard Hit by Killsec Ransomware Exposing 600GB of Data

Incident Date: Sep 10, 2024

Attack Overview
VICTIM
Rupicard
INDUSTRY
Finance
LOCATION
India
ATTACKER
Killsec
FIRST REPORTED
September 10, 2024

Rupicard Falls Victim to Killsec Ransomware Attack

Rupicard, an innovative financial service provider in India, has recently fallen victim to a ransomware attack orchestrated by the notorious cybercriminal group Killsec. The attack has resulted in the exfiltration of over 600 GB of sensitive data, including millions of credit score records.

Overview of Rupicard

Rupicard is a financial technology startup based in Bengaluru, India, focusing on providing accessible credit card solutions tailored for the Indian market. The company aims to democratize access to credit cards, particularly for those who are financially underserved, including small businesses and individuals in Tier-2 cities. Their primary offering, the Rupicard FD Credit Card, operates on a secured credit model, helping users build or improve their credit scores.

Attack Details

The ransomware group Killsec has claimed responsibility for the attack on Rupicard via their dark web leak site. The attackers successfully infiltrated Rupicard's systems and exfiltrated a significant amount of sensitive data. The perpetrators have left a message indicating their willingness to negotiate, urging the company to contact them for offers.

About Killsec

Killsec, also known as Kill Security, is a ransomware group known for targeting various industries and countries. The group has been active in sectors such as government, manufacturing, defense, professional services, banking & finance, and sports & gaming. They use a variety of communication channels and crypto wallets to conduct their operations, often demanding significant extortion amounts from their victims.

Vulnerabilities and Penetration

Rupicard, being a small to medium-sized enterprise with a workforce ranging from 11 to 50 employees, may have been particularly vulnerable to such an attack due to limited cybersecurity resources. The exact method of penetration remains unclear, but common tactics include phishing emails, exploiting software vulnerabilities, and leveraging weak security protocols. The attack on Rupicard underscores the importance of comprehensive cybersecurity measures, especially for financial institutions handling sensitive data.

Sources

See Halcyon in action

Interested in getting a demo?
Fill out the form to meet with a Halcyon Anti-Ransomware Expert!

1
2
3
Let's get started
1
1
2
3
1
1
2
2
3
Back
Next
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.