Supply chain β›“ Supply Chain

HSBC Third-Party Breach (May 2024)

πŸ“… 2024-05-01 🏒 Baton Systems
Primary Source β†—

Incident Details

Alleged HSBC, Barclays data exposed by IntelBroker. Hackread reports that IntelBroker has exposed sensitive data allegedly stolen from major UK-based international financial services firms Barclays and HSBC following a purported attack against a third-party contractor last month that was conducted along with Sanggiero. Information compromised in the intrusion against the third party included both banks’ source codes, database files, compiled JAR files, certification files, SQL files, JSON configuration files, and email addresses, according to IntelBroker, which already leaked a substantial amount of data on BreachForums resulting in their proliferation across various Russian forums. Third-party company: Baton Systems.

Technical Details

Initial Attack Vector
Compromise of third-party service provider / vendor relationship
Vendor / Product
Baton Systems
Supply Chain Attack
βœ… Confirmed third-party / vendor compromise

Timeline

  1. 2024-05-01 Breach occurred
  2. 2024-05-10 Publicly disclosed