Menu
Browse

Cyber Threat Actor: Absa employee

Actor Type Location Known Incidents
 Icon
Insider - Disgruntled
South Africa
0 incidents
Profile

The threat actor is known by the alias “Absa employee” and is located in South Africa, where they worked as a credit analyst for the Absa financial services group. In this role the individual had legitimate access to the bank’s risk‑modeling processes and used that access to exfiltrate personal information belonging to approximately 200,000 clients. The compromised data included clients’ identification numbers, residential addresses, contact details, and descriptions of vehicles purchased on finance, while PIN codes and passwords were reported as unaffected. Absa disclosed that the activity affected about two percent of its retail customer base and that the breach was first detected on October 27, 2020, with a public announcement delayed by one month to avoid jeopardizing ongoing court proceedings. Following the discovery, Absa obtained court orders for search and seizure operations at various premises, recovered all devices containing the stolen data, and wiped those devices clean of the information. The bank’s chief security officer described the actor as someone who was trusted and whose access was part of their normal job duties, noting that the purchasers of the data might attempt to use it for fraudulent purposes.

The actor’s targeting is explicitly limited to the financial services sector within South Africa, as evidenced by the abuse of internal access at a South African‑based bank. The observed tactics involve insider threat behavior, specifically the misuse of legitimate credentials and privileged access to copy and transfer sensitive customer data to external parties; no malware families, exploit tools, or external intrusion vectors are mentioned in the source material. No public attribution to a state sponsor, criminal consortium, or other affiliations has been established for this individual. The most notable operation associated with the actor is the Absa personal‑data sale incident, which involved the illicit transfer of 200,000 client records to third parties and prompted a coordinated legal and technical response by the bank. While the article references a separate large‑scale Experian breach that impacted millions of South Africans, that event is not attributed to this actor and is provided only as contextual background.

Incidents
Attributed incidents available to members
0 incidents
Sources
Sources available to members
1 source