Cyber Incident Victim: ABN Amro
Date:
May 2024
Location:
Netherlands
Summary
A cyberattack targeting ABN Amro's communications supplier, AddComm, potentially exposed customer data, prompting the bank to suspend services with the vendor while maintaining close coordination. Affected customers were directly notified, with cybersecurity experts engaged and regulators informed about the breach. The unauthorized access occurred over a multi-day period before being contained, though the specific compromised data remains unidentified; the attackers no longer retain system access.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
In mid-May 2024, ABN Amro disclosed a potential data breach involving customer information following a cyberattack targeting AddComm, its external supplier specializing in customer communication services. The attack occurred between May 5 and May 17, during which unauthorized actors gained access to AddComm's systems. ABN Amro immediately suspended all services with AddComm upon discovering the compromise while maintaining close coordination with the affected vendor to assess the situation. The bank promptly notified customers whose data might have been exposed to the attackers, though neither AddComm nor ABN Amro confirmed the specific nature or scope of the compromised information at the initial stage. AddComm emphasized that cybercriminals no longer retained access to their systems following containment efforts.

ABN Amro activated its cybersecurity experts to investigate the incident's ramifications and reported the breach to relevant regulatory authorities as part of mandatory compliance protocols. The bank prioritized direct communication with potentially impacted clients but did not publicly disclose the number of affected individuals or specific data categories involved. AddComm acknowledged uncertainty regarding which client datasets were exfiltrated during the intrusion window, leaving the full extent of data exposure unverified. The incident disrupted ABN Amro's customer communication workflows due to the suspension of AddComm's services, though operational continuity measures mitigated broader service interruptions. Both organizations maintained ongoing investigations to determine the attack's origin and finalize damage assessments while adhering to regulatory disclosure requirements.
