Hackers attempted to profit from their initial breach of Valartis Bank Liechtenstein by threatening to reveal critical customer data.
The sensitive nature of the data that thieves are stealing makes the situation very worrisome.
In reality, it is said that cybercriminals are using the threat of releasing account data to coerce victims into not paying ransom payments.
According to reports, the cybercriminals are requesting up to 10% of account balances in order to keep client information private.
The media-published letters verify the hacker's plan to use threats of exposing purportedly improper activities, such as tax avoidance, as a means of blackmailing the victims.
Source: https://securityaffairs.com/53891/data-breach/liechtenstein-banks-ransomware.html
TPRM report: https://scoringcyber.rankiteo.com/company/valartis-group
"id": "val204551123",
"linkid": "valartis-group",
"type": "Breach",
"date": "11/2016",
"severity": "100",
"impact": "",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'industry': 'Financial Services',
'location': 'Liechtenstein',
'name': 'Valartis Bank Liechtenstein',
'type': 'Bank'}],
'attack_vector': 'Unspecified',
'data_breach': {'sensitivity_of_data': 'High',
'type_of_data_compromised': ['Account Data',
'Customer Information']},
'description': 'Hackers attempted to profit from their initial breach of '
'Valartis Bank Liechtenstein by threatening to reveal critical '
'customer data. The sensitive nature of the data that thieves '
'are stealing makes the situation very worrisome. '
'Cybercriminals are using the threat of releasing account data '
'to coerce victims into not paying ransom payments. According '
'to reports, the cybercriminals are requesting up to 10% of '
'account balances in order to keep client information private. '
"The media-published letters verify the hacker's plan to use "
'threats of exposing purportedly improper activities, such as '
'tax avoidance, as a means of blackmailing the victims.',
'impact': {'data_compromised': ['Account Data', 'Customer Information']},
'motivation': 'Financial Gain, Blackmail',
'ransomware': {'ransom_demanded': ['Up to 10% of account balances']},
'threat_actor': 'Unidentified Cybercriminals',
'title': 'Valartis Bank Liechtenstein Data Breach and Blackmail Attempt',
'type': 'Data Breach, Blackmail'}