DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

(UPDATED) Texas bank attacked with DoppelPaymer ransomware — attackers’ report

Posted on March 1, 2020 by Dissent

Update 2:  The attackers have confirmed that they had named the wrong bank and that the victim bank is Community Development Bank (in Minnesota).

UPDATE 1:  Amanda Tavackoli SVP, Communication for TBK Bank has responded with the following statement:

I’m responding to your request for information regarding the DoppelPaymer claim.

Reports that CD Bank has been a target of ransomware are false. Our Information Security team and our core provider have conducted a thorough review and have found no evidence that CD Bank was compromised. The evidentiary documents are unrelated to CD Bank or any of its related entities.

At the present time, then, DataBreaches.net is not sure what is going on but with TBK/CDBank’s firm denial, this bears further inquiry.  Stay tuned…

Previous post:

It’s getting uglier out there.  Both Maze Team and the DoppelPaymer ransomware teams seem to be attempting to increase pressure on their victims by giving them less time to respond before their name and data get publicly revealed.

For its part, although Maze Team is clearly active and updating their site on a frequent, if not daily, basis, Maze Team has not replied to a number of queries this site has sent it about the removal of some victims’ names from their site and what that means.  So far, only one of their HIPAA-covered victims seems to have reported their attack to HHS/OCR. DataBreaches.net is monitoring the situation to see if the other victims that Maze Team had identified to me in email eventually disclose publicly.  Most of Maze Team’s victims have not replied at all to inquiries from this site asking them to confirm or deny the claimed hacks and none of the victims Maze Team identified to me that have not come forward have any notices on their websites, either. Ironically, perhaps, Crossroads Technologies, identified as a breached entity by Personal Touch Home Care as the source of their reported breach, does not have any notice on their website about the incident while it continues to advertise its security and help with HIPAA compliance.

Elsewhere, and as noted previously, DoppelPaymer attackers are experimenting with using the same kind of website naming and dumping approach.

One of their targets appears to be CD Bank, the online division of Texas-based TBK Bank, SSB.  NOTE: See the Updates at the top of this post. The victim bank is Community Development Bank, not CD Bank. 

CD Bank has not responded to inquiries sent to it on February 27 and on February 28.  An inquiry was also sent to TBK Bank today through their website. NOTE:  They responded. See first update above this post.

In the interim, the attackers have dumped more of the bank’s data every day, with some files containing personal and financial information of bank customers, as the following redacted screencaps illustrate:

The DoppelPaymer attackers named CDBank as one of their victims and started dumping data files, but it was not CD Bank that they attacked.  Follow-up revealed that it was Community Development Bank.
One page of a file dumped by DoppelPaymer attackers. The full account numbers and customer names have been redacted by DataBreaches.net.

Neither the CD Bank nor the TBK Bank’s websites give any indication of anything amiss or any cyberattack, and as noted above, neither have confirmed nor refuted any claimed attack.  NOTE:  See updates.  They were not attacked.

This post was edited several times post-publication to correct attributions and to keep readers apprised.

Category: Financial SectorMalwareU.S.

Post navigation

← GA: Records reveal City of Cartersville paid ransomware attackers $380K
Hit with ransomware, Prince Edward Island notifies residents and continues recovery efforts →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Massachusetts hacker to plead guilty to PowerSchool data breach
  • Cyberattack brings down Kettering Health phone lines, MyChart patient portal access (1)
  • Gujarat ATS arrests 18-year-old for cyberattacks during Operation Sindoor
  • Hackers Nab 15 Years of UK Legal Aid Applicant Data
  • Supplier to major UK supermarkets Aldi, Tesco & Sainsbury’s hit by cyber attack with ransom demand
  • UK: Post Office to compensate hundreds of data leak victims
  • How the Signal Knockoff App TeleMessage Got Hacked in 20 Minutes
  • Cocospy stalkerware apps go offline after data breach
  • Ex-NSA bad-guy hunter listened to Scattered Spider’s fake help-desk calls: ‘Those guys are good’
  • Former Sussex Police officer facing trial for rape charged with 18 further offences relating to computer misuse

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Telegram Gave Authorities Data on More than 20,000 Users
  • Police secretly monitored New Orleans with facial recognition cameras
  • Cocospy stalkerware apps go offline after data breach
  • Drugmaker Regeneron to acquire 23andMe out of bankruptcy
  • Massachusetts Senate Committee Approves Robust Comprehensive Privacy Law
  • Montana Becomes First State to Close the Law Enforcement Data Broker Loophole
  • Privacy enforcement under Andrew Ferguson’s FTC

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.