Admiral Money

Admiral Money

The Cybernews research team discovered a configuration mistake in the OCR Labs system that exposed sensitive data.

The data leak had an effect on Defence Bank, Bloom Money, Admiral Money, MA Money, and Reed.

Using exposed data, threat actors might be able to infiltrate the backend infrastructure of banks and, as a result, the infrastructure of their clients.

Given that financial services are the main target of cybercriminals, businesses and their customers are seriously at risk.

Cybernews contacted OCR Labs, who then fixed the issue.

Source: https://securityaffairs.com/144514/data-breach/ocr-labs-data-leak.html

TPRM report: https://scoringcyber.rankiteo.com/company/admiral-money

"id": "adm42429523",
"linkid": "admiral-money",
"type": "Data Leak",
"date": "04/2023",
"severity": "60",
"impact": "3",
"explanation": "Attack with significant impact with internal employee data leaks"
{'affected_entities': [{'industry': 'Finance',
                        'name': 'Defence Bank',
                        'type': 'Financial Institution'},
                       {'industry': 'Finance',
                        'name': 'Bloom Money',
                        'type': 'Financial Institution'},
                       {'industry': 'Finance',
                        'name': 'Admiral Money',
                        'type': 'Financial Institution'},
                       {'industry': 'Finance',
                        'name': 'MA Money',
                        'type': 'Financial Institution'},
                       {'industry': 'Finance',
                        'name': 'Reed',
                        'type': 'Financial Institution'}],
 'attack_vector': 'Configuration Mistake',
 'data_breach': {'sensitivity_of_data': 'High',
                 'type_of_data_compromised': 'Sensitive Data'},
 'description': 'The Cybernews research team discovered a configuration '
                'mistake in the OCR Labs system that exposed sensitive data. '
                'The data leak affected Defence Bank, Bloom Money, Admiral '
                'Money, MA Money, and Reed. Using exposed data, threat actors '
                'might be able to infiltrate the backend infrastructure of '
                'banks and, as a result, the infrastructure of their clients. '
                'Given that financial services are the main target of '
                'cybercriminals, businesses and their customers are seriously '
                'at risk. Cybernews contacted OCR Labs, who then fixed the '
                'issue.',
 'impact': {'data_compromised': 'Sensitive Data',
            'operational_impact': 'Potential infiltration of backend '
                                  'infrastructure'},
 'motivation': 'unknown',
 'post_incident_analysis': {'corrective_actions': 'Issue fixed by OCR Labs',
                            'root_causes': 'Configuration Mistake'},
 'references': [{'source': 'Cybernews'}],
 'response': {'remediation_measures': 'Issue fixed by OCR Labs'},
 'threat_actor': 'unknown',
 'title': 'OCR Labs Data Leak',
 'type': 'Data Leak'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.