https://www.theregister.com/2024/07/09/evolve_lockbit_attack/ # # Sign in / up The Register(r) -- Biting the hand that feeds IT # # # Topics Security Security All SecurityCyber-crimePatchesResearchCSO (X) Off-Prem Off-Prem All Off-PremEdge + IoTChannelPaaS + IaaSSaaS (X) On-Prem On-Prem All On-PremSystemsStorageNetworksHPCPersonal TechCxOPublic Sector (X) Software Software All SoftwareAI + MLApplicationsDatabasesDevOpsOSesVirtualization (X) Offbeat Offbeat All OffbeatDebatesColumnistsScienceGeek's GuideBOFHLegalBootnotesSite NewsAbout Us (X) Special Features Special Features All Special Features Malware Month Cloud Infrastructure Week Cybersecurity Month Blackhat and DEF CON Sysadmin Month The Reg in Space Emerging Clean Energy Tech Week Spotlight on RSA Energy Efficient Datacenters Vendor Voice Vendor Voice Vendor Voice All Vendor Voice Amazon Web Services (AWS) New Horizon in Cloud Computing DDN Google Cloud Data Transformation Google Gemini Hewlett Packard Enterprise: Edge-to-Cloud Platform Intel vPro VMware (X) Resources Resources Whitepapers Webinars & Events Newsletters [cybercrime] Cyber-crime 3 comment bubble on white Evolve Bank & Trust confirms LockBit stole 7.6 million people's data 3 comment bubble on white Making cyberattack among the largest ever recorded in finance industry icon Connor Jones Tue 9 Jul 2024 // 13:52 UTC # Evolve Bank & Trust says the data of more than 7.6 million customers was stolen during the LockBit break-in in late May, per a fresh filing with Maine's attorney general. The filing lists the total number of persons affected (including residents) at 7,640,112. It's the first time Evolve has confirmed the scale of the data theft - which affected at least three of its major partners, past and present - and it expects the number to rise as its investigations continue. [cybercrime] Both Wise and Affirm, international money transfer and buy-now-pay-later companies respectively, confirmed in SEC filings last week that they were both materially affected by the break-in at Evolve. [cybercrime] [cybercrime] Wise severed ties with Evolve last year but was still impacted by the incident. Mercury also suggested it could be affected. However, none of the company's partners have yet revealed the extent to which the ransomware crew that cops allege is headed by Dmitry Khoroshev managed to pillage their customers' data. [cybercrime] The Register approached all 15 partners listed on Evolve's website and only received a response from one other company, Melia, and the last we heard it was probing any potential impact rather than confirming anything. As for Evolve, its letter to customers reads: "On May 29, 2024, Evolve identified that some of its systems were not working properly. "While it initially appeared to be a hardware failure, we subsequently learned it was unauthorized activity. [cybercrime] "Evolve promptly initiated its incident response processes and stopped the attack. No new unauthorized activity on Evolve's systems has been identified since May 31, 2024. An investigation with assistance from a cybersecurity firm was initiated to investigate what happened and what data may have been impacted. Evolve also notified law enforcement and worked to add further protections to harden its systems." The Banking-as-a-Service provider went on to say that although it may have enacted its incident response playbook when it spotted signs of foul play, it took the vendor roughly four months to detect the intrusion. "There is no evidence that the threat actors accessed any customer funds, but it appears the threat actors did access and download customer information from Evolve's databases and a file share during periods in February and May 2024." The letters sent to affected individuals are usually attached to filings with state attorneys general, but typically omit details such as the specific data types stolen in each case. Some customers may have had names and addresses stolen, while others may have had their social security numbers taken as well, for example. We know from Evolve's earlier disclosure that SSNs, bank account numbers, and contact information "for most" of its personal banking customers and partners may be affected, as well as some staff. That disclosure, last updated on July 8, also stated that this week's notification letters are expected to be a first round with additional, smaller rounds of notifications to come in the following weeks. Evolve has offered impacted individuals 24 months of credit monitoring, as is often the case in major data leaks. Victims have until October 31 to enroll for these services, and the full instructions on how to do so are included in an email to be sent in the next two weeks. * Eldorado ransomware-as-a-service gang targets Linux, Windows systems * Avast secretly gave DoNex ransomware decryptors to victims before crims vanished * Affirm fears customer info pilfered during ransomware raid at Evolve Bank * Indonesian government datacenter locked down in $8M ransomware rumble Rounding off the letter, Evolve went on to say that it "had a significant number of cybersecurity measures in place," which have now been strengthened even further. The incident, however, came against the backdrop of a stern telling off from the US Federal Reserve Board on June 14, less than a fortnight before it announced the data had been stolen. Following a review of Evolve in 2023, the board wasn't happy at all with the Arkansas-headquartered company for a number of reasons including "deficiencies" in anti-money laundering, risk management, and consumer compliance programs. It was assessed to have engaged in "unsafe and unsound banking practices," particularly in relation to the absence of an effective risk management framework for its array of partners, among other issues, which resulted in an enforcement action being issued. This, of course, came just a few weeks after Evolve became aware that LockBit was rummaging through its systems for the best part of four months - a hardly ideal 2024 for the finance firm. Misery loves company At least Evolve is not alone in the pits of the "data breach" filings this week. Financial Business and Consumer Solutions (FBCS) also updated Maine's attorney general on the state of its investigation regarding its own data exposure for the second time in as many weeks. At the end of June, we reported how the debt collector's situation was going from bad to worse, and now it's worse still with the update indicating the number of affected individuals has now surpassed 4 million. The February attack on FBCS was originally slated to have affected around 2 million people, according to its first filing in April. By the end of June, that number had risen to just north of 3.4 million, and now it stands at 4,050,711, to be precise. The data stolen includes names, SSNs, dates of birth, account information, and identity documents, but no recognized cybercrime operation has taken credit for what the FBCS called a "cyber incident." (r) Get our Tech Resources # Share More about * Cybercrime * Cybersecurity * Ransomware More like these x More about * Cybercrime * Cybersecurity * Ransomware Narrower topics * NCSC * REvil * RSA Conference * Wannacry Broader topics * Security More about # Share 3 comment bubble on white COMMENTS More about * Cybercrime * Cybersecurity * Ransomware More like these x More about * Cybercrime * Cybersecurity * Ransomware Narrower topics * NCSC * REvil * RSA Conference * Wannacry Broader topics * Security TIP US OFF Send us news --------------------------------------------------------------------- Other stories you might like Avast secretly gave DoNex ransomware decryptors to victims before crims vanished Updated Good riddance to another pesky tribe of miscreants Malware Month8 Jul 2024 | 9 Cancer patient forced to make terrible decision after Qilin attack on London hospitals Exclusive Skin-sparing mastectomy and breast reconstruction scrapped as result of ransomware at supplier Malware Month5 Jul 2024 | 65 Europol nukes nearly 600 IP addresses in Cobalt Strike crackdown Private sector helped out with week-long operation - but didn't touch China Malware Month4 Jul 2024 | 8 Ransomware thieves beware Why Object First and Veeam tick the box for encryption and immutability Sponsored Feature [cybercrime] Affirm fears customer info pilfered during ransomware raid at Evolve Bank Number of partners acknowledging data theft continues to rise Malware Month2 Jul 2024 | 2 Eldorado ransomware-as-a-service gang targets Linux, Windows systems US orgs bear the brunt of attacks by probably-Russian crew Malware Month9 Jul 2024 | 16 Patelco banking services AWOL amid ransomware ruckus Late fees? Don't worry, the credit union has you covered Malware Month3 Jul 2024 | 2 UK and US cops band together to tackle Qilin's ransomware shakedowns Attacking the NHS is a very bad move Malware Month25 Jun 2024 | 26 Qilin: We knew our Synnovis attack would cause a healthcare crisis at London hospitals Interview Cybercriminals claim they used a zero-day to breach pathology provider's systems Cyber-crime20 Jun 2024 | 25 Not-so-OpenAI allegedly never bothered to report 2023 data breach security in brief Also: F1 authority breached; Prudential victim count skyrockets; a new ransomware actor appears; and more Security8 Jul 2024 | 5 Latest Ghostscript vulnerability haunts experts as the next big breach enabler There's also chatter about whether medium severity scare is actually code red nightmare Research5 Jul 2024 | 25 Europol says mobile roaming tech is making its job too hard Privacy measures apparently helping criminals evade capture Cyber-crime5 Jul 2024 | 36 The Register icon Biting the hand that feeds IT About Us* * Contact us * Advertise with us * Who we are Our Websites* * The Next Platform * DevClass * Blocks and Files Your Privacy* * Cookies Policy * Privacy Policy * Ts & Cs * Do not sell my personal information Situation Publishing Copyright. All rights reserved (c) 1998-2024 no-js