CSIDB logo
Incident

Axis Bank

Incident posture

Attack window
Oct 2016
Location
India
Status
Historical
CIA posture
Available to members
Updated
2025-12-09 00:00

Linked entities

Victim
Axis Bank
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Oct 2016
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Axis Bank, India's third-largest private bank, experienced a cybersecurity breach involving unauthorized external access to its systems, detected by a Kaspersky Lab researcher during an unrelated investigation. The intrusion originated from a non-Indian IP address and appeared limited to preliminary network reconnaissance without compromise of critical systems or unauthorized fund transfers. The institution confirmed no financial losses to customer accounts and engaged security firm EY for further analysis while reporting the incident to national banking authorities. This event coincided with multiple cybersecurity incidents affecting other major Indian banks, including mass debit card cancellations due to suspected ATM malware compromises and a separate theft at another bank where partial funds were later recovered.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

In October 2016, Axis Bank, India's third-largest private bank, publicly disclosed a cybersecurity breach after being alerted by an external researcher. The incident was discovered accidentally by a Kaspersky Lab security researcher during an unrelated investigation in September 2016, when evidence of unauthorized access to some bank systems was identified. Upon notification from Kaspersky, Axis Bank conducted an internal review that confirmed an intrusion via an unauthorized login originating from a non-Indian IP address. The bank promptly reported the incident to India's banking regulator, the Reserve Bank of India, following standard disclosure protocols. Initial analysis indicated the attacker had gained access to portions of the bank's network but had not progressed beyond initial infiltration stages at the time of detection. No evidence was found suggesting compromise of core banking systems or customer transaction platforms during this preliminary investigation.

Further examination revealed the attacker appeared to be conducting reconnaissance activities within the network, a phase typically involving scanning for vulnerabilities and mapping system architecture to enable lateral movement toward high-value targets. Bank officials confirmed no unauthorized fund transfers occurred and stated customer accounts remained secure throughout the incident. Axis Bank engaged professional services firm EY to assist with forensic analysis and investigation continuation. This breach occurred amid heightened cybersecurity concerns across India's banking sector, coinciding with the State Bank of India's mass debit card blockage affecting 600,000 customers due to suspected ATM malware infections, and following Union Bank of India's July 2016 incident involving offshore account compromises. The Axis Bank incident highlighted network access vulnerabilities but demonstrated containment before financial theft or systemic disruption could occur.

Sources

Sources available to members: 1 source.

CSIDB