Hasty Briefsbeta

Bilingual

Email compromise that wiped half a billion $

6 hours ago
  • TripleX ransomware group breached Bank of Baroda via a compromised employee email account, exfiltrating 1 TB of sensitive data.
  • The leaked data includes customer PII (Aadhaar, PAN, photos), financial records, audit reports, and loan documents, posing identity theft risks.
  • The attack likely involved phishing, MFA bypass (e.g., AiTM phishing), OAuth abuse, or endpoint compromise, exploiting excessive permissions.
  • Five technical scenarios explain how a single mailbox led to massive data exfiltration, including session token theft and cloud collaboration pivoting.
  • TripleX operates as a data-extortion collective, not traditional ransomware, publicly leaking data for ideological and financial motives.
  • The group previously targeted PT Bank Negara Indonesia, indicating a pattern of preying on large financial institutions.
  • Post-breach, Android banking malware and phishing campaigns were observed, exploiting the breach for follow-on attacks.
  • TripleX's motives include retaliatory extortion, underground market monetization, brand elevation, and potential stock market manipulation.
  • The incident highlights a shift toward identity-based attacks that bypass traditional email security, requiring continuous evaluation of user behavior and context.

Related

Loading…