DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

(UPDATED) Texas bank attacked with DoppelPaymer ransomware — attackers’ report

Posted on March 1, 2020 by Dissent

Update 2:  The attackers have confirmed that they had named the wrong bank and that the victim bank is Community Development Bank (in Minnesota).

UPDATE 1:  Amanda Tavackoli SVP, Communication for TBK Bank has responded with the following statement:

I’m responding to your request for information regarding the DoppelPaymer claim.

Reports that CD Bank has been a target of ransomware are false. Our Information Security team and our core provider have conducted a thorough review and have found no evidence that CD Bank was compromised. The evidentiary documents are unrelated to CD Bank or any of its related entities.

At the present time, then, DataBreaches.net is not sure what is going on but with TBK/CDBank’s firm denial, this bears further inquiry.  Stay tuned…

Previous post:

It’s getting uglier out there.  Both Maze Team and the DoppelPaymer ransomware teams seem to be attempting to increase pressure on their victims by giving them less time to respond before their name and data get publicly revealed.

For its part, although Maze Team is clearly active and updating their site on a frequent, if not daily, basis, Maze Team has not replied to a number of queries this site has sent it about the removal of some victims’ names from their site and what that means.  So far, only one of their HIPAA-covered victims seems to have reported their attack to HHS/OCR. DataBreaches.net is monitoring the situation to see if the other victims that Maze Team had identified to me in email eventually disclose publicly.  Most of Maze Team’s victims have not replied at all to inquiries from this site asking them to confirm or deny the claimed hacks and none of the victims Maze Team identified to me that have not come forward have any notices on their websites, either. Ironically, perhaps, Crossroads Technologies, identified as a breached entity by Personal Touch Home Care as the source of their reported breach, does not have any notice on their website about the incident while it continues to advertise its security and help with HIPAA compliance.

Elsewhere, and as noted previously, DoppelPaymer attackers are experimenting with using the same kind of website naming and dumping approach.

One of their targets appears to be CD Bank, the online division of Texas-based TBK Bank, SSB.  NOTE: See the Updates at the top of this post. The victim bank is Community Development Bank, not CD Bank. 

CD Bank has not responded to inquiries sent to it on February 27 and on February 28.  An inquiry was also sent to TBK Bank today through their website. NOTE:  They responded. See first update above this post.

In the interim, the attackers have dumped more of the bank’s data every day, with some files containing personal and financial information of bank customers, as the following redacted screencaps illustrate:

The DoppelPaymer attackers named CDBank as one of their victims and started dumping data files, but it was not CD Bank that they attacked.  Follow-up revealed that it was Community Development Bank.
One page of a file dumped by DoppelPaymer attackers. The full account numbers and customer names have been redacted by DataBreaches.net.

Neither the CD Bank nor the TBK Bank’s websites give any indication of anything amiss or any cyberattack, and as noted above, neither have confirmed nor refuted any claimed attack.  NOTE:  See updates.  They were not attacked.

This post was edited several times post-publication to correct attributions and to keep readers apprised.

Category: Financial SectorMalwareU.S.

Post navigation

← GA: Records reveal City of Cartersville paid ransomware attackers $380K
Hit with ransomware, Prince Edward Island notifies residents and continues recovery efforts →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Department of Justice says Berkeley Research Group data breach may have exposed information on diocesan sex abuse survivors
  • Masimo Manufacturing Facilities Hit by Cyberattack
  • Education giant Pearson hit by cyberattack exposing customer data
  • Star Health hacker claims sending bullets, threats to top executives: Reports
  • Nova Scotia Power hit by cyberattack, critical infrastructure targeted, no outages reported
  • Georgia hospital defeats data-tracking lawsuit
  • 60K BTC Wallets Tied to LockBit Ransomware Gang Leaked
  • UK: Legal Aid Agency hit by cyber security incident
  • Public notice for individuals affected by an information security breach in the Social Services, Health Care and Rescue Services Division of Helsinki
  • PowerSchool paid a hacker’s extortion demand, but now school district clients are being extorted anyway (3)

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • ARC sells airline ticket records to ICE and others
  • Clothing Retailer, Todd Snyder, Inc., Settles CPPA Allegations Regarding California Consumer Privacy Act Violations
  • US Customs and Border Protection Plans to Photograph Everyone Exiting the US by Car
  • Google agrees to pay Texas $1.4 billion data privacy settlement
  • The App Store Freedom Act Compromises User Privacy To Punish Big Tech
  • Florida bill requiring encryption backdoors for social media accounts has failed
  • Apple Siri Eavesdropping Payout Deadline Confirmed—How To Make A Claim

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.