Cyber Security News

BASHE Ransomware Allegedly Leaked ICICI Bank Customers Data

A major cyber threat looms over Indian financial giant ICICI Bank as the notorious BASHE ransomware group, also known as Eraleign (APT73), claims responsibility for a significant data breach.

The group has allegedly obtained sensitive customer information and set a ransom deadline for January 24, 2025.

The Claim

The revelation surfaced during independent research conducted on dark web forums, where BASHE published statements asserting they had breached ICICI Bank’s internal systems.

According to the Cyber Security News report, the breach compromised a vast trove of private and financial customer data, potentially including personally identifiable information (PII), account details, and banking records.

ICICI Bank data breachICICI Bank data breach
ICICI Bank data breach

Although the group has not specified the exact volume or nature of the data stolen, the claims have raised concerns about the security of one of India’s most prominent multinational financial institutions.

Investigate Real-World Malicious Links & Phishing Attacks With Threat Intelligence Lookup - Try for Free

ICICI Bank’s Response

As of now, ICICI Bank has not publicly acknowledged the breach or validated these claims. The organization has neither issued an official statement nor disclosed any incidents related to unauthorized access or ransomware attacks.

Without confirmation from the bank, the authenticity of BASHE’s claims remains uncertain.

ICICI Bank customers are advised to monitor their accounts vigilantly for any unauthorized transactions or suspicious activity.

leaked data

Those concerned about data security should consider resetting passwords and enabling additional layers of protection, such as two-factor authentication (2FA), if not already implemented.

The BASHE ransomware group, operating under the alias Eraleign (APT73), has been among the most active and sophisticated cyber threat actors in recent years.

Known for targeting critical infrastructure, government institutions, and financial organizations worldwide, the group typically employs ransomware to encrypt sensitive files and demands hefty ransoms in exchange for decryption keys.

In this case, BASHE has reportedly issued a ransom deadline, suggesting that ICICI Bank must comply with their demands by January 24, 2025, to avoid the public release of compromised data.

The alleged breach and its implications are solely based on dark web research and unverified claims made by the BASHE group. Until ICICI Bank confirms or denies the incident, the information should be considered speculative.

This event raises serious questions about cybersecurity readiness in the financial sector, especially with ransomware attacks becoming more frequent and destructive.

Customers and financial institutions alike are reminded of the importance of staying vigilant against evolving cyber threats.

Integrating Application Security into Your CI/CD Workflows Using Jenkins & Jira -> Free Webinar

Divya

Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Recent Posts

Landmark Admin Suffers Major Breach, Exposing Data of 1.6M+ Users

Landmark Admin, LLC (“Landmark”), a Texas-based third-party administrator for life insurance carriers, has confirmed that…

2 hours ago

SquareX to Reveal Critical Data Splicing Attack at BSides SF, Exposing Major DLP Vulnerability

SquareX researchers Jeswin Mathai and Audrey Adeline will be disclosing a new class of data exfiltration techniques at BSides San…

2 hours ago

Firefox Fixes High-Severity Vulnerability Causing Memory Corruption via Race Condition

Mozilla has released Firefox 137.0.2, addressing a high-severity security flaw that could potentially allow attackers…

4 hours ago

Tails 6.14.2 Released with Critical Fixes for Linux Kernel Vulnerabilities

The Tails Project has urgently released Tails 6.14.2, addressing critical security vulnerabilities in the Linux kernel…

5 hours ago

APT29 Hackers Use GRAPELOADER in New Attack Against European Diplomats

Check Point Research (CPR) has uncovered a new targeted phishing campaign employing GRAPELOADER, a sophisticated…

6 hours ago

Chinese Hackers Unleash New BRICKSTORM Malware to Target Windows and Linux Systems

A sophisticated cyber espionage campaign leveraging the newly identified BRICKSTORM malware variants has targeted European…

6 hours ago