Supply chain
⛓ Supply Chain
Ascension Third-Party Breach (January 2019)
Primary Source ↗Incident Details
Millions of bank loan and mortgage documents have leaked online | TechCrunch. A trove of more than 24 million financial and banking documents, representing tens of thousands of loans and mortgages from some of the biggest banks in. The server, running an Elasticsearch database, had more than a decade’s worth of data, containing loan and mortgage agreements, repayment schedules and other highly sensitive financial and tax documents that reveal an intimate insight into a person’s financial life. But it wasn’t protected with a password, allowing anyone to access and read the massive cache of documents. Third-party company: OpticsML.
Technical Details
- Initial Attack Vector
- Compromise of third-party service provider / vendor relationship
- Vendor / Product
- OpticsML
- Supply Chain Attack
- ✅ Confirmed third-party / vendor compromise
Timeline
- 2019-01-01 Breach occurred
- 2019-01-23 Publicly disclosed