DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Maze ransomware operators claim to have stolen millions of credit cards from Banco BCR

Posted on May 1, 2020 by Dissent

Lawrence Abrams reports on a new “press release” from the Maze ransomware operators. The release was posted yesterday and claims that the Maze Team had successfully attacked Banco BCR, the state-owned bank of Costa Rico in August, 2019

The attackers claim that the bank never complied with its obligations to notify other banks and regulators. And when the attackers revisited the situation in February, 2020, they found that they could still access data.

This time, they claim, they did not encrypt the data, saying that it “was at least incorrect during the world pandemic,” but claim to have stolen a few years of data, including 11 million credit cards.

Of these credit cards, 4 million are stated to be unique and 140,000 allegedly belong to people from the USA.

The attackers posted a sample of redacted credit card numbers as proof.

Read more on BleepingComputer. If you had or have an account with that bank, you should contact them to check on the status of your account. You may want to freeze it. Then again, if their security is as bad as Maze Team would have us believe, you may wish to consider canceling it altogether.

DataBreaches.net reached out to BancoBCR yesterday to request a comment on the claims, but has not received any reply from their media contact or any of the four other executives and employees who were contacted. I see that Abrams hasn’t received any reply yet, either.

This post will likely either be updated or a follow-up post written as more information becomes available.

No related posts.

Category: Financial SectorHackMalwareU.S.

Post navigation

← Clop ransomware leaks ExecuPharm’s files after failed ransom
Sixth Annual Data Security Incident Response Report Released – Managing Enterprise Risks and Leveraging Data in a Digital World →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Air Force Employee Pleads Guilty to Conspiracy to Disclose Unlawfully Classified National Defense Information
  • UK police arrest four in connection with M&S, Co-op and Harrods cyberattacks (1)
  • At U.S. request, France jails Russian basketball player Daniil Kasatkin on suspicion of ransomware conspiracy
  • Avantic Medical Lab hacked; patient data leaked by Everest Group
  • Integrated Oncology Network victim of phishing attack; multiple locations affected (2)
  • HHS’ Office for Civil Rights Settles HIPAA Privacy and Security Rule Investigation with Deer Oaks Behavioral Health for $225k and a Corrective Action Plan
  • HB1127 Explained: North Dakota’s New InfoSec Requirements for Financial Corporations
  • Credit reports among personal data of 190,000 breached, put for sale on Dark Web; IT vendor fined
  • Five youths arrested on suspicion of phishing
  • Russia Jailed Hacker Who Worked for Ukrainian Intelligence to Launch Cyberattacks on Critical Infrastructure

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • How to Build on Washington’s “My Health, My Data” Act
  • Department of Justice Subpoenas Doctors and Clinics Involved in Performing Transgender Medical Procedures on Children
  • Google Settles Privacy Class Action Over Period Tracking App
  • ICE Is Searching a Massive Insurance and Medical Bill Database to Find Deportation Targets
  • Franklin, Tennessee Resident Sentenced to 30 Months in Federal Prison on Multiple Cyber Stalking Charges
  • On July 7, Gemini AI will access your WhatsApp and more. Learn how to disable it on Android.
  • German court awards Facebook user €5,000 for data protection violations

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.