Computing Deutsche Bank Investigates Ransomware Breach by Unsafe Group
Article Content
- •Unsafe ransomware group claims to have breached Deutsche Bank's external service provider.
- •Screenshots released show sensitive employee data, but customer information status is unclear.
- •Deutsche Bank confirms its internal systems remain unaffected and is investigating the incident.
Deutsche Bank is probing a cybersecurity incident involving an external service provider after the ransomware group Unsafe claimed to have breached the bank and leaked employee data. The group published screenshots on a dark web leak site, allegedly showing database extracts containing sensitive employee information, including email addresses and password hashes. Although the bank stated that its internal systems were not compromised, the incident raises concerns about potential phishing attacks and further compromises. Cybernews researchers noted that while the data appears to be limited to employee records, it could still pose significant risks. Unsafe operates under a ransomware-as-a-service model and has recently resurfaced after a quiet period, targeting organizations in multiple countries. Deutsche Bank is collaborating with the affected third-party provider to investigate and mitigate risks.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Cl0p Ransomware Gang, Emotet and Deutsche Bank in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Ryuk Ransomware: Ongoing Threat to Large Organizations Ryuk ransomware, attributed to the Russian group Wizard Spider, continues to target large organizations, particularly in sectors like healthcare and government. The malware is delivered through phishing attacks and often relies on other malware like Emotet or TrickBot for initial access. Once inside a network, Ryuk…
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…