Hackers gained access to the network of Banco BCR, the state-owned Bank of Costa Rica, and stole 11 million credit card credentials along with other data.
This attack was conducted by the operators of the Maze Ransomware.
Of these credit cards, 4 million are stated to be unique and 140,000 allegedly belong to people from the USA.
As proof of this theft, Maze posted what they say are 240 credit card numbers, with the last four digits removed, along with expiration dates and credit card verification codes (CVC).
TPRM report: https://scoringcyber.rankiteo.com/company/banco-de-costa-rica
"id": "ban1941291222",
"linkid": "banco-de-costa-rica",
"type": "Breach",
"date": "02/2020",
"severity": "100",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '11 million credit card holders',
'industry': 'Financial Services',
'location': 'Costa Rica',
'name': 'Banco BCR',
'type': 'Bank'}],
'data_breach': {'data_exfiltration': True,
'number_of_records_exposed': '11 million',
'personally_identifiable_information': 'Credit card numbers, '
'expiration dates, '
'CVCs',
'sensitivity_of_data': 'High',
'type_of_data_compromised': 'Credit card credentials'},
'description': 'Hackers gained access to the network of Banco BCR, the '
'state-owned Bank of Costa Rica, and stole 11 million credit '
'card credentials along with other data. This attack was '
'conducted by the operators of the Maze Ransomware. Of these '
'credit cards, 4 million are stated to be unique and 140,000 '
'allegedly belong to people from the USA. As proof of this '
'theft, Maze posted what they say are 240 credit card numbers, '
'with the last four digits removed, along with expiration '
'dates and credit card verification codes (CVC).',
'impact': {'data_compromised': ['11 million credit card credentials',
'Other data'],
'payment_information_risk': 'High'},
'ransomware': {'data_exfiltration': True, 'ransomware_strain': 'Maze'},
'threat_actor': 'Maze Ransomware operators',
'title': 'Banco BCR Data Breach',
'type': 'Data Breach, Ransomware'}