Frame-14

Privacy Ninja

        • DATA PROTECTION

        • CYBERSECURITY

        • Secure your network against various threat points. VA starts at only S$1,000, while VAPT starts at S$4,000. With Price Beat Guarantee!

        • API Penetration Testing
        • Enhance your digital security posture with our approach that identifies and addresses vulnerabilities within your API framework, ensuring robust protection against cyber threats targeting your digital interfaces.

        • On-Prem & Cloud Network Penetration Testing
        • Boost your network’s resilience with our assessment that uncovers security gaps, so you can strengthen your defences against sophisticated cyber threats targeting your network

        • Web Penetration Testing
        • Fortify your web presence with our specialised web app penetration testing service, designed to uncover and address vulnerabilities, ensuring your website stands resilient against online threats

        • Mobile Penetration Testing
        • Strengthen your mobile ecosystem’s resilience with our in-depth penetration testing service. From applications to underlying systems, we meticulously probe for vulnerabilities

        • Cyber Hygiene Training
        • Empower your team with essential cybersecurity knowledge, covering the latest vulnerabilities, best practices, and proactive defence strategies

        • Thick Client Penetration Testing
        • Elevate your application’s security with our thorough thick client penetration testing service. From standalone desktop applications to complex client-server systems, we meticulously probe for vulnerabilities to fortify your software against potential cyber threats.

        • Source Code Review
        • Ensure the integrity and security of your codebase with our comprehensive service, meticulously analysing code quality, identifying vulnerabilities, and optimising performance for various types of applications, scripts, plugins, and more

        • Email Spoofing Prevention
        • Check if your organisation’s email is vulnerable to hackers and put a stop to it. Receive your free test today!

        • Email Phishing Excercise
        • Strengthen your defense against email threats via simulated attacks that test and educate your team on spotting malicious emails, reducing breach risks and boosting security.

        • Cyber Essentials Bundle
        • Equip your organisation with essential cyber protection through our packages, featuring quarterly breached accounts monitoring, email phishing campaigns, cyber hygiene training, and more. LAUNCHING SOON.

Pacific City Bank Discloses Ransomware attack claimed by AvosLocker

Pacific City Bank Discloses Ransomware attack claimed by AvosLocker

Pacific City Bank (PCB), one of the largest Korean-American community banking service providers in America, has disclosed a ransomware incident that took place last month.

The bank is circulating notices to inform its clients of a security breach it identified on August 30, 2021, which they claim to have addressed promptly.

Sensitive details leaked

PCB’s internal investigation on what happened was concluded on September 7, 2021, and it revealed that ransomware actors had unfortunately obtained the following information from its systems:

  • Loan application forms
  • Tax return documents
  • W-2 information of client firms
  • Payroll records of client firms
  • Full names
  • Addresses
  • Social Security Numbers
  • Wage and tax details

As PCB clarifies, not all clients have been impacted the same, as each customer has provided different documents and details that were stored in the compromised systems.

Also Read: 6 ways to recognize a potential phishing scam and what to do if you receive one

Also, whether or not this incident affects the entire clientele of the bank or just a small subset has not been determined. We have reached out to the bank for clarifications, but we have not heard back yet.

The recipients of these notices are advised to remain vigilant against incoming communications and monitor their financial account statements and credit reports for signs of fraud.

Additionally, the bank is offering one year of free credit monitoring and identity theft protection services through Equifax, with instructions on how to enroll enclosed in the letters. Follow these instructions without deviation to avoid getting scammed by actors who may attempt to seize the opportunity.

An AvosLocker victim

While Pacific City Bank did not reveal the name of the ransomware group behind the September incident, AvosLocker is claiming the attack and has published an entry on their data leak site

The date of the incident is set on September 4, 2021, so the five days of difference may just be the “grace” period of the initial negotiation round, during which ransomware actors typically avoid making announcements.

AvosLocker announcing PCB as their victim.
AvosLocker announcing Pacific City Bank as their victim. – BleepingComputer

The files that were eventually posted on the extortion portal are showing what PCB has now admitted as compromised, so there are no disparities there.

AvosLocker is one of the newer ransomware operators, appearing in the wild this summer, calling for affiliates on various underground forums to join the RaaS.

Also Read: How does ransomware happen? Here are 7 ways to prevent them

The group uses a multi-threaded ransomware strain that enables them to encrypt files fast, while the payload is deployed manually by the attacker. Although the AvosLocker features some string and API obfuscation to evade static detection, it is generally “naked”, coming without a crypting layer.

For more details on the AvosLocker and what you can do if you’re hit by this ransomware family, check out our support topic

0 Comments

KEEP IN TOUCH

Subscribe to our mailing list to get free tips on Data Protection and Data Privacy updates weekly!

Personal Data Protection

REPORTING DATA BREACH TO PDPC?

We have assisted numerous companies to prepare proper and accurate reports to PDPC to minimise financial penalties.
×

Hello!

Click one of our contacts below to chat on WhatsApp

× Chat with us