Deutsche Bank AG has confirmed that a data breach on one of its service providers has exposed its customers’ data in a likely MOVEit Transfer data-theft attack.
The bank has been notified of a security incident at one of its external service providers, which operates their account switching service in Germany.
In addition to the service provider, over 100 companies in more than 40 countries are potentially affected. The incident is related to Clop ransomware’s wave of MOVEit attacks.
However, the banking giant assured that the Deutsche Bank’s systems were not affected by the incident at its service provider at any time.
The public German bank, which is one of the largest in the world, having total assets of $1.5 trillion and an annual net income of $6.3 billion, stated that the incident impacted customers in Germany who used its account switching service in 2016, 2017, 2018, and 2020.
Although the number of impacted clients has not been determined, the bank states that only a limited amount of personal data was exposed due to the security incident.
The bank is investigating the causes of the data leak and taking targeted action to improve its data security precautions to avoid similar incidents from impacting its clients in the future.
Deutsche Bank stated that threat actors cannot gain access to accounts using the exposed data, but they might try to initiate unauthorized direct debits.
In response to this risk, the bank has extended the period of unauthorized direct debit returns to 13 months, allowing its customers ample time to identify, report, and receive reimbursement for unauthorized transactions.
According to German media outlets, the security incident on the unnamed service provider used by Deutsche Bank also impacted other major banks and financial service providers, including Commerzbank, Postbank, Comdirect, and ING.
Image Credits : Agenzia Nova















Comments