Menu
Browse

Cyber Incident Victim: GenialMoney

Date:

Sep 2022

Location:

Italy

Summary

An Italian financial services firm experienced a significant data breach involving the theft of approximately 68 GB of sensitive information, comprising over 23,000 files in formats including PDF, DOCX, and XLS. The cybercriminal group Kelvin Security claimed responsibility for the attack, subsequently offering the stolen data for sale on the underground forum Breach Forums. This group, active since 2020 and known for targeting Italian organizations, operates as grey hat hackers specializing in data exfiltration, access sales, and trading stolen databases. The incident aligns with their prior operations against other domestic entities and international corporations, leveraging underground platforms to monetize compromised information. Breach Forums emerged as a prominent cybercrime hub following the takedown of Raid Forums, attracting threat actors seeking illicit data markets.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 5 motives 1 technique
Threat Actor Type Location
1 actor Available to members Available to members

Description

On September 28, 2022, the Italian financial company GenialMoney, based in Lamezia Terme, was confirmed as a victim of a cyberattack by the hacking group Kelvin Security. The group publicly advertised the stolen data for sale on Breach Forums, a prominent underground cybercrime forum established in March 2022 as a replacement for the seized Raid Forums platform. The compromised data amounted to approximately 68 GB, comprising over 23,000 files in PDF, DOCX, and XLS formats. Kelvin Security provided a sample of the stolen data within their forum post to facilitate sales negotiations, alongside contact details for potential buyers. The group, described as grey hat hackers, has operated since at least 2020 and previously targeted other Italian organizations, including a Vodafone Italia supplier, RP Company, and E-City Group. Their historical activities included the 2020 breach of a BMW Group supplier, where they exfiltrated and sold data belonging to 384,000 customers on Raid Forums.

Cyber Incident Image

The incident exposed sensitive GenialMoney documents to underground markets, increasing risks of fraud or secondary attacks against the company and its clients. Breach Forums, where the data was listed, had rapidly grown to over 1,500 members since its creation by threat actor "pompompurin" following law enforcement’s seizure of Raid Forums. The forum attracted former Raid Forums users who maintained identical usernames and avatars, suggesting continuity in illicit trading practices. Kelvin Security’s broader operations included selling network access, proof-of-concept exploits, and stolen databases beyond the GenialMoney breach. Cybersecurity monitoring entity RedHotCyber (RHC) committed to tracking developments but reported no immediate containment actions or public response from GenialMoney. The breach highlighted the persistent threat posed by established cybercrime forums facilitating large-scale data trafficking among Western threat actors.

Sources
Sources available to members
1 source