/security

News and resources on cyber and physical threats to banks and fintechs worldwide.

Western Alliance Bank falls victim to zero-day breach

Phoenix-based business bank Western Alliance has notified customers of a data breach caused by a zero-day vulnerability in third party file transfer software.

  1 Be the first to comment

Western Alliance Bank falls victim to zero-day breach

Editorial

This content has been selected, created and edited by the Finextra editorial team based upon its relevance and interest to our community.

The break-in came to light in January when stolen records were leaked by hackers online.

Western Alliance has declined to specify the software, although the bank was one of hundreds of companies and organizations named by the Clop ransomware gang in October after the group claimed it was behind the exploitation of a vulnerability impacting the Cleo file sharing tool.

The files included data flowing through the file transfer software between October 12-24, 2024, shortly before the bank was advised to patch its systems due to the emergence of a zero-day vulnerability.

The hackers managed to exfiltrate the personal details of nearly 22,000 customers, capturing individuals names, Social Security numbers, dates of birth, financial account numbers, driver's license numbers, tax identification numbers, and/or passport.

In an SEC filing, the bank states: "The Company will work with clients who may have been impacted and will make appropriate notifications to impacted individuals. Although the Company continues to investigate and has not determined the full impact of this incident, at this time the incident has not had a material impact on the Company’s business or operations.

Sponsored [New Report] Using modern technology platforms to create an AI-driven bank

Comments: (0)

[New Impact Study] Cross-Border Payments: How is the market addressing G20 targets?Finextra Promoted[New Impact Study] Cross-Border Payments: How is the market addressing G20 targets?