Sunday, April 13, 2025
HomeCyber Security NewsBASHE Ransomware Allegedly Leaked ICICI Bank Customers Data

BASHE Ransomware Allegedly Leaked ICICI Bank Customers Data

Published on

SIEM as a Service

Follow Us on Google News

A major cyber threat looms over Indian financial giant ICICI Bank as the notorious BASHE ransomware group, also known as Eraleign (APT73), claims responsibility for a significant data breach.

The group has allegedly obtained sensitive customer information and set a ransom deadline for January 24, 2025.

The Claim

The revelation surfaced during independent research conducted on dark web forums, where BASHE published statements asserting they had breached ICICI Bank’s internal systems.

- Advertisement - Google News

According to the Cyber Security News report, the breach compromised a vast trove of private and financial customer data, potentially including personally identifiable information (PII), account details, and banking records.

ICICI Bank data breach
ICICI Bank data breach

Although the group has not specified the exact volume or nature of the data stolen, the claims have raised concerns about the security of one of India’s most prominent multinational financial institutions.

Investigate Real-World Malicious Links & Phishing Attacks With Threat Intelligence Lookup - Try for Free

ICICI Bank’s Response

As of now, ICICI Bank has not publicly acknowledged the breach or validated these claims. The organization has neither issued an official statement nor disclosed any incidents related to unauthorized access or ransomware attacks.

Without confirmation from the bank, the authenticity of BASHE’s claims remains uncertain.

ICICI Bank customers are advised to monitor their accounts vigilantly for any unauthorized transactions or suspicious activity.

leaked data
leaked data

Those concerned about data security should consider resetting passwords and enabling additional layers of protection, such as two-factor authentication (2FA), if not already implemented.

The BASHE ransomware group, operating under the alias Eraleign (APT73), has been among the most active and sophisticated cyber threat actors in recent years.

Known for targeting critical infrastructure, government institutions, and financial organizations worldwide, the group typically employs ransomware to encrypt sensitive files and demands hefty ransoms in exchange for decryption keys.

In this case, BASHE has reportedly issued a ransom deadline, suggesting that ICICI Bank must comply with their demands by January 24, 2025, to avoid the public release of compromised data.

The alleged breach and its implications are solely based on dark web research and unverified claims made by the BASHE group. Until ICICI Bank confirms or denies the incident, the information should be considered speculative.

This event raises serious questions about cybersecurity readiness in the financial sector, especially with ransomware attacks becoming more frequent and destructive.

Customers and financial institutions alike are reminded of the importance of staying vigilant against evolving cyber threats.

Integrating Application Security into Your CI/CD Workflows Using Jenkins & Jira -> Free Webinar

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Latest articles

Threat Actors Manipulate Search Results to Lure Users to Malicious Websites

Cybercriminals are increasingly exploiting search engine optimization (SEO) techniques and paid advertisements to manipulate...

Hackers Imitate Google Chrome Install Page on Google Play to Distribute Android Malware

Cybersecurity experts have unearthed an intricate cyber campaign that leverages deceptive websites posing as...

Dangling DNS Attack Allows Hackers to Take Over Organization’s Subdomain

Hackers are exploiting what's known as "Dangling DNS" records to take over corporate subdomains,...

HelloKitty Ransomware Returns, Launching Attacks on Windows, Linux, and ESXi Environments

Security researchers and cybersecurity experts have recently uncovered new variants of the notorious HelloKitty...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

Threat Actors Manipulate Search Results to Lure Users to Malicious Websites

Cybercriminals are increasingly exploiting search engine optimization (SEO) techniques and paid advertisements to manipulate...

Hackers Imitate Google Chrome Install Page on Google Play to Distribute Android Malware

Cybersecurity experts have unearthed an intricate cyber campaign that leverages deceptive websites posing as...

Dangling DNS Attack Allows Hackers to Take Over Organization’s Subdomain

Hackers are exploiting what's known as "Dangling DNS" records to take over corporate subdomains,...