Data leak

Truist Bank Data Breach (2023 Intrusion, 2024 Dark Web Disclosure)

πŸ“… 2023-10-01
Primary Source β†—

Incident Details

Truist Bank, a major US financial institution formed by the merger of SunTrust Banks and BB&T, confirmed in June 2024 that its systems had been breached in October 2023. The breach came to light when a threat actor posted stolen data on dark web forums, offering approximately 65,000 employee records for $1 million. Stolen data included names, SSNs, account numbers, dates of birth, and addresses. Truist customers were separately affected by the FBCS (Financial Business and Consumer Solutions) third-party breach in February 2024 (a distinct incident). Truist confirmed the October 2023 breach was a separate event from the FBCS supply-chain exposure. Financial sector; highlights the long dwell time before dark web disclosure of intrusions.

Technical Details

Initial Attack Vector
Unknown intrusion in October 2023; data later posted for sale on dark web forums in June 2024

Timeline

  1. 2023-10-01 Breach occurred
  2. 2024-06-01 Publicly disclosed
  3. 2024-06-01 Customers notified