Categories: SecurityWorkspace

Hackers Hold Belgian Credit Provider To Ransom

Hackers are attempting to extort Belgian credit provider Elantis after claiming to have breached the company’s systems.

In a statement on Pastebin, the hackers threatened to publish customer information if the bank did not pay €150,000 (£121,000) before Friday. According to reports, Elantis confirmed the data breach on Thursday, but is refusing to give in to the blackmail attempt.

Credentials obtained

The hackers say they have obtained log-in credentials and tables with online loan applications holding a variety of data, including names, job descriptions and income information. The hackers claimed the data was stored unencrypted on the company’s servers.

“While this could be called ‘blackmail,’ we prefer to think of it as an ‘idiot tax’ for leaving confidential data unprotected on a web server,” the statement said.

The only question that remains now, the statement continued, “is after they carelessly treated their clients’ data, will Dexia act to prevent their clients’ data from being published online, or is their clients’ confidentiality worth less to them than EUR 150,000?”

Belfius, the parent company that owns Elantis, told ZDNet UK that it had informed the Federal Computer Crime Unit in Brussels as well as local police in Liege of the situation. Up to 3,700 customers and brokers may have been affected, and they have been informed of the probable breach, according to the bank.

“We say this is blackmail,” Belfius spokeswoman Moniek Delvou told ZDNet UK. “The ransom has to be paid today… We will not pay.”

Payment demanded

The hackers initially sent Elantis an email last Friday telling the company they had possession of information about Elantis brokers and customers, and then demanded payment. Elantis responded by shutting down its servers, Delvou reportedly said.

Mark Bower, vice president at data security firm Voltage Security, questioned why the confidential data was not encrypted.

“Financial institutions are under many data privacy regulations – encryption being a requirement for making sure that in the event of a breach, the stolen data is actually useless to the hacker, which would have diffused a situation like this,” he said.

“Cases like this continue to raise awareness of the shortcomings of traditional infrastructure security in keeping sensitive data safe. The strategy should have been to protect the data end-to-end … After a breach like this, the expensive and disruptive consequences are just starting and will continue for a long time, including extensive audits, remediation, loss of customer confidence, regulation fines and more,” Bower said.

“The sad reality here is that the real victim is the bank’s customers, not the bank,” said Carole Theriault, senior security consultant at Sophos, in a blog post. “It is the customer data that is at risk. Their only fault was partnering with the wrong bank at the wrong time.”

How well do you know Internet security? Try our quiz and find out!

Brian Prince eWEEK USA 2014. Ziff Davis Enterprise Inc. All Rights Reserved

Recent Posts

OpenAI In Talks With California Over For-Profit Shift

OpenAI reportedly begins early talks with California attorney general over complex transition from nonprofit to…

15 hours ago

EU To Assess Apple’s iPad Compliance Plans

European Commission says it will review Apple's iPad compliance with DMA rules as it seeks…

15 hours ago

James Dyson Says ‘Spiteful’ Budget Will Kill Start-Ups

James Dyson delivers most high-profile criticism so far of Labour's first Budget that raises £40bn…

16 hours ago

Nvidia, Meta Ask Supreme Court To Axe Investor Lawsuits

Nvidia, Meta bring cases before US Supreme Court this month seeking tighter limits on investors'…

16 hours ago

Nvidia To Replace Intel On Dow Jones Industrial Average

Nvidia to replace Intel this week on Dow Jones Industrial Average after years of turmoil…

17 hours ago

Toyota-Backed Joby Flies ‘Air Taxi’ In Japan

Joby Aviation and Toyota Motor complete demonstration flight in Shizuoka as companies prepare to bring…

17 hours ago