Hatch Bank says 140,000 customers had data stolen after breach

ransomware avast
(Image credit: Avast)

Hatch Bank has become the second company to suffer the consequences of the data breach that happened at GoAnywhere MFT, once again demonstrating just how dangerous supply chain attacks can be.

The financial technology firm has filed a report with the Attorney General's office in which it said that threat actors took advantage of a flaw in GoAnywhere MFT to steal sensitive data on almost 140,000 customers. 

"On January 29, 2023, Fortra experienced a cyber incident when they learned of a vulnerability located in their software," Hatch Bank told affected customers. "On February 3, 2023, Hatch Bank was notified by Fortra of the incident and learned that its files contained on Fortra’s GoAnywhere site were subject to unauthorized access."

Stealing Social Security numbers

GoAnywhere MFT is a popular file-sharing service developed by Fortra and used by large businesses to share sensitive files, securely.

According to Hatch, the attackers managed to obtain customer names, and Social Security Numbers. To help remedy the problem, the company is providing free access to credit monitoring services for 12 months, to affected customers.

Hatch did not say the name of the group behind the attack, but according to BleepingComputer, it was the Clop ransomware gang. The group confirmed the attack to the publication, saying it used a zero-day vulnerability in Fortra's GoAnywhere MFT secure file-sharing platform to steal data for almost a fortnight. The zero-day it mentions is CVE-2023-0669, a remote code execution flaw that was patched in early February this year. 

While BleepingComputer could not verify Clop’s claims, Huntress Threat Intelligence Manager Joe Slowik apparently found evidence that links GoAnywhere MFT and TA505, the hacking group known for deploying Clop ransomware.

Clop was also the one claiming responsibility for the attack on the initial major victim, Community Health Systems, saying the zero-day in GoAnywhere MFT allowed it to breach as many as 130 companies.

Via: BleepingComputer

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Data leak
US utility giant says MOVEit hack exposed stolen data
Lock on Laptop Screen
Clop ransomware lists Cleo cyberattack victims
Someone holding a passport with two boarding passes inside it
Top digital loan firm security slip-up puts data of 36 million users at risk
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
59 organizations reportedly victim to breaches caused by Cleo software bug
ID theft
Over a million patients potentially hit after another US healthcare provider hit by cyberattack
A digital themed isometric showing a neon padlock in the foreground, and a technological diagram of a processor logic board in the background.
LastPass 2022 hack fallout continues with millions of dollars more reportedly stolen
Latest in Security
Google Chrome dark mode
Google updates Chrome extension rules to ban affiliate link injection without user action or benefit
Abstract image of robots working in an office environment including creating blueprint of robot arm, making a phone call, and typing on a keyboard
This worrying botnet targets unsecure TP-Link routers - thousands of devices already hacked
Avast cybersecurity
UK cybersecurity sector could be worth £13bn, research shows
An option to add Ambient Music buttons to the iOS 18.4 Control Center.
Apple fixes dangerous zero-day used in attacks against iPhones and iPads
Trump
Hackers are abusing $TRUMP tokens to lure victims in to new phishing scam
An American flag flying outside the US Capitol building against a blue sky
Sean Plankey selected as CISA director by President Trump
Latest in News
Two Android phones on a green and blue background showing Google Messages
Struggling with slow Google Messages photo transfers? Google says new update will make 'noticeable difference'
Elayne, Egwene, and Nynaeve dressed regally and on horseback in The Wheel of Time season 3
'There's a reason why we do it': The Wheel of Time showrunner responds to fans who are still upset over the Prime Video show's plot alterations
Google Pixel 9
Android 16 could bring an improved Samsung DeX-style desktop mode to more phones
An Nvidia GeForce RTX 4060 Ti
Nvidia could unleash RTX 5060 and 5060 Ti GPUs on PC gamers tomorrow, but there’s no sign of rumored RTX 5050 yet
AI writing
ChatGPT just wrote the most beautiful short story, and I wonder what I'm even doing here
Google Chrome dark mode
Google updates Chrome extension rules to ban affiliate link injection without user action or benefit