Cyber Incident Victim: Targobank
Date:
Nov 2023
Location:
Germany
Summary
Targobank blocked online banking access for approximately 6,000 customers following unauthorized access attempts detected by its security systems, preventing account compromises. Affected users could no longer access their accounts via the bank's app or web browser, though card-based transactions remained operational. The institution initiated a credential reset process, contacting impacted customers by postal mail with instructions for generating new login credentials to restore secure access. The bank confirmed no further breaches occurred beyond the blocked intrusion attempts, maintaining that its defenses successfully neutralized the threat.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On or around November 4, 2023, Targobank's security systems detected unauthorized access attempts targeting customer online banking accounts. The bank identified malicious actors attempting to compromise these accounts through unspecified methods. In response, Targobank proactively blocked online banking access for approximately 6,000 affected customers as a containment measure. Customers first noticed disruptions starting the weekend of November 4-5, when they became unable to access accounts through either the mobile application or web browsers. The bank confirmed these access restrictions were intentional security measures rather than technical failures. Card-based payment systems and other banking functions remained operational throughout the incident. A Targobank spokesperson stated their security systems successfully prevented the unauthorized access attempts, with no evidence of successful account compromises or financial losses reported.

The incident exclusively impacted online banking credentials, requiring affected customers to obtain new login information. Targobank initiated postal communications to all 6,000 impacted customers in the days following the detection, outlining procedures for credential replacement. No digital notifications or website advisories were immediately published regarding the incident. The bank emphasized maintaining "maximum security" through credential resets while confirming no secondary systems or customer data beyond online banking access were compromised. Service restoration depended on customers receiving and activating replacement credentials through the mailed instructions. The containment strategy focused exclusively on credential revocation without disclosing whether additional authentication enhancements were implemented. Targobank characterized the incident as successfully mitigated with no operational impact beyond temporary online banking access restrictions for the affected customer group.
