Banco Pan became aware of a data breach that made sensitive personal information available in the public domain is estimated to be 250GB.
Exposed personal data includes scanned ID and social security cards, as well as documents provided as proof of address and service request forms filled out by customers.
Banco Pan said it doesn't own the vulnerable environment, rather, it is managed by a commercial partner of the bank.
After careful analysis of its security systems accompanied by independent consultancy, it has become evident that the server is not owned by Pan and that no intrusion into the bank's infrastructure has been found.
Source: https://www.zdnet.com/article/brazilian-banking-users-exposed-by-250gb-data-leak/
TPRM report: https://scoringcyber.rankiteo.com/company/banco-pan
"id": "ban2342423",
"linkid": "banco-pan",
"type": "Data Leak",
"date": "07/2019",
"severity": "85",
"impact": "3",
"explanation": "Attack with significant impact with internal employee data leaks"
{'affected_entities': [{'industry': 'Financial Services',
'name': 'Banco Pan',
'type': 'Bank'}],
'data_breach': {'file_types_exposed': ['scanned ID',
'social security cards',
'proof of address',
'service request forms'],
'personally_identifiable_information': True,
'sensitivity_of_data': 'High',
'type_of_data_compromised': ['scanned ID',
'social security cards',
'proof of address',
'service request forms']},
'description': 'Banco Pan became aware of a data breach that made sensitive '
'personal information available in the public domain is '
'estimated to be 250GB. Exposed personal data includes scanned '
'ID and social security cards, as well as documents provided '
'as proof of address and service request forms filled out by '
"customers. Banco Pan said it doesn't own the vulnerable "
'environment, rather, it is managed by a commercial partner of '
'the bank. After careful analysis of its security systems '
'accompanied by independent consultancy, it has become evident '
'that the server is not owned by Pan and that no intrusion '
"into the bank's infrastructure has been found.",
'impact': {'data_compromised': ['scanned ID',
'social security cards',
'proof of address',
'service request forms']},
'response': {'third_party_assistance': ['independent consultancy']},
'title': 'Banco Pan Data Breach',
'type': 'Data Breach'}