Millions of credit card details stolen from the Bank of Costa Rica
Maze ransomware actors have breached inside Banco BCR, a state-owned Bank of Costa Rica and have stolen 11 million credit card details. These Maze actors were already behind the number of cyberattacks across the world in recent times, the data breaches of Cognizant, Bouygues Construction, Cyber insurer Chubb and UK-based medical agency.
Maze have also mentioned in their website that they had already breached Banco BCR in August 2019, and stole some information but did not encrypt the data as that could damage the firm heavily. Furthermore, it appears that the bank had not secured their servers and networks till now, which allowed Maze actors to breach the bank network again in February 2020 and steal plenty of credit card credentials. Considering the global pandemic, the hackers did not encrypt the data for the second time as well.
Out of the 11 million credit cards, 4 million are unique and 140,000 belongs to the USA residents. Moreover, to ensure the proof of theft Maze has posted the credit card details of 240 people including validity information and credit card verification codes but without the final four digits of the credit card.
It appears the actors have tried to contact the bank and demand for the ransom, but has not received any response for their messages, and so Maze actors have mentioned, if there is no response from the bank then the stolen information will be sold in the dark web. If people need to confirm whether their card is secured, they need to contact the Banco BCR, and confirm the safety of their credit cards. It is appropriate for the Banco BCR to publish the data breach information to the public and its customers.
Robust cybersecurity protocols are a must all time, especially financial institutions, should be on high alert. Banking trojans have become a prevalent security issue in recent times, and these institutions need to improvise their cybersecurity strategies, policies, configurations and awareness to keep their organization in the game.
Subscribe to our newsletter for daily alerts on cyber events, you can also follow us on Facebook, Linkedin, Instagram, Twitter and Reddit.