Spanish Bank Globalcaja Hit By Ransomware Attack

Spanish bank Globalcaja confirmed last Friday that it suffered a cyber incident involving a ransomware attack on some local systems. The Play ransomware group claims to be behind the attack.

Officially statement The company said on Twitter (in Spanish) that the attack occurred last Thursday, prompting the financial institution to activate its security protocols.

Globalcaja reassured customers that their accounts and contracts were not compromised by the ransomware attack and that the normal functioning of their e-banking platform, Ruralvía, would not be affected.

The company also ensured that customers could safely continue their financial operations through online banking and use available ATMs without any worries.

As part of precautionary measures, Globalcaja temporarily disabled certain office workstations to contain the incident and limit its potential impact.

“The financial sector is an attractive target for ransomware attacks due to the vast amount of data and critical services managed by financial institutions,” said Martin Mackay, CRO of Versa Networks.

“Targeting customer information and threatening to leak data not only results in financial damage, but can also jeopardize a bank’s value and reputation,” he said.

The executive added that while it is still being determined whether Globalcaja responded to Play’s ransom demands, the key point in this scenario is to not give in to any demands.

Read more about ransomware: Ransomware encryption rates reach new heights

“Paying a ransom does not guarantee that the stolen data will be returned or leaked, it will only facilitate further cybercriminal activity,” McKay advised.

Global Kaha stressed that it was actively working to normalize the situation and thoroughly analyze the incident.

“The only good thing is that Globalcaja had security protocols in place,” added Mackay.

Banking institutions that have not yet implemented security protocols should consider implementing measures such as network segmentation to limit the movement of malware and minimize the impact of a breach, the CRO said.

“Furthermore, maintaining complete visibility across the network can make a big difference in quickly identifying and responding to cyber threats,” McKay concluded.

Rebecca Moody, head of data research at Comparitech, said there has been an increase in high-profile attacks against financial institutions this year.

Notable incidents include the cyberattack on Tri Counties Bank in the United States, later claimed by BlackBasta, the attack on Latitude Financial in Australia, which may have compromised about 14 million records, and the LockBit attack on Fullerton in India (ransom demanding $3 million). ) and Bank Syariah India (a $20 million demand).

“As seen in the latest lawsuit against Globalcaja, attacks against this type of organization are of particular concern due to the highly sensitive data held by the organization,” Moody added. “Financial institutions should be commended for not bowing to the demands of hackers, while at the same time helping customers take all necessary steps to protect themselves against identity theft and other types of fraud. I also need to.”

Editorial image credit: Manuel Esteban / Shutterstock.com



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *