Data breach
InterBank
- Records
- 3,317,881
- Breach date
- 30 October 2024Estimated
- Added
- 30 October 2024
What was exposed
5 types of data · 1 puts you at serious risk
- Email addresses3,317,881
- Names3,317,881
- Home addresses3,317,881
- Phone numbers3,317,881
- Social security numbers3,317,881
About this breach
In late October 2024, Interbank, one of Peru's largest banks, confirmed that a third party exposed data belonging to a group of its customers without the bank's authorization. According to our investigation team, the breach affects an estimated 3.3 million individuals. A threat actor using the handle "kzoldyck" claimed responsibility for stealing roughly 3.7 terabytes of data from the bank's systems and began publishing samples on BreachForums after what the actor described as a failed two-week extortion negotiation. The actor claimed to hold records on more than 3 million customers, though the bank has not confirmed that figure or the full scope of the theft.
October 30, 2024: Interbank and its Plin digital wallet suffered service outages, and reports surfaced of an attack on the bank's systems that afternoon.
October 31, 2024: Infobae reported that Interbank acknowledged the exposure after the data appeared on a cybercrime forum, and that the actor described failed extortion talks with the bank.
November 11, 2024: La República reported that investigators believed the attacker entered through a server operated by Interbank's technology vendor New Relic, and that Peru's banking regulator, data protection authority, and Indecopi had opened inquiries.
What Information Was Compromised?
Our analysis found the following data types in this breach: government identification numbers (recorded in the index as Social Security numbers; for Interbank customers these correspond to Peruvian national ID documents), email addresses, phone numbers, names, and home addresses. Each of these was found for all 3,317,881 individuals in the dataset.
Not every individual is affected by every type of data listed here.
The threat actor additionally claimed, in posts reported by BleepingComputer, to possess account identifiers, birth dates, IP addresses, credit card numbers with CVV codes and expiry dates, transaction information, and plaintext login credentials, along with internal API, LDAP, and Azure credentials. These claims have not been independently verified, and Interbank has said the exposed information does not allow transactions on customer accounts.
What Are the Potential Risks for Affected Individuals?
Exposed names, addresses, phone numbers, and identification numbers are the raw material for identity fraud, targeted phishing, and account takeover attempts. If the actor's claims about plaintext credentials and card details are accurate, the risks would extend to unauthorized account access and card fraud. Attackers who hold both identification numbers and contact details can craft convincing messages that appear to come from the bank. Anyone who reused their Interbank password elsewhere should treat those other accounts as at risk as well.
What Is InterBank Doing in Response?
Interbank confirmed the incident publicly and said it deployed additional security measures, including special monitoring of customer operations and information. General manager Carlos Tori said in a video statement that the exposed information does not put customer accounts or financial products at risk, and the bank assured customers that deposits are secure. The bank temporarily limited some services during the incident and later reported that most channels were operating again. Peruvian authorities, including the Superintendencia de Banca, Seguros y AFP and the national data protection authority, opened investigations, and Interbank representatives told Peru's Congress that the bank was investigating the origin and impact of the attack.
What Should You Do If You Were Affected?
Change your Interbank password immediately, and change it anywhere else you reused it.
Turn on any available multi-factor authentication on your banking and email accounts.
Watch for phishing messages that reference Interbank, your accounts, or recent "security issues." Verify by calling the bank through official channels, not through links in messages.
Review your bank and card statements for transactions you did not make, and report anything suspicious to the bank right away.
Consider monitoring whether your identification number or other personal details appear in unauthorized use, such as unfamiliar loan applications.
In the news
- BleepingComputer: Interbank confirms data breach following failed extortion, data leakbleepingcomputer.com (opens in a new tab)
- Infobae: Caso Interbankinfobae.com (opens in a new tab)
- La República: Ciberataque a Interbanklarepublica.pe (opens in a new tab)
- Peru's National Cybersecurity Center: Integrated Security Alert 252-2024cdn.www.gob.pe (opens in a new tab)
