Cyber Incident Victim: East West Bank
Date:
Jun 2023
Location:
United States of America
Summary
The East Western Bank was hit by a cyberattack exploiting a vulnerability in the MOVEit file transfer tool. The attack, attributed to the Russia-linked Clop ransomware gang, resulted in the compromise of sensitive information. The incident was part of a larger campaign targeting multiple organizations, including US government agencies. The attackers posted a list of affected organizations on their dark web leak site, but did not threaten to extort or release stolen data.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actor | Type | Location |
|---|---|---|
| 1 actor | Available to members | Available to members |
Description
The East Western Bank was recently hit by a cyberattack that exploited a vulnerability in the MOVEit file transfer tool. This attack was attributed to the Russia-linked Clop ransomware gang, which has been known to target organizations in various sectors. The incident resulted in the compromise of sensitive information, although the exact nature and extent of the data breach are not publicly known.

The attack on East Western Bank was part of a larger campaign that targeted multiple organizations, including several US government agencies. The attackers exploited a vulnerability in the MOVEit tool, which is widely used for secure file transfers. The vulnerability allowed the attackers to gain unauthorized access to the affected organizations' systems and data. The Clop ransomware gang is known for its sophisticated tactics and techniques, and this attack was no exception.
The attackers posted a list of affected organizations on their dark web leak site, which included East Western Bank and several other prominent organizations. However, unlike in some previous cases, the attackers did not threaten to extort or release stolen data. Instead, they seemed to focus on claiming responsibility for the attack and highlighting their capabilities. This approach is consistent with the Clop gang's modus operandi, which often involves seeking to embarrass and disrupt their targets rather than extorting them for financial gain.
The incident highlights the ongoing risks and challenges associated with cyberattacks, particularly those that target vulnerabilities in widely used software tools. The MOVEit vulnerability exploited by the attackers was likely present in many organizations' systems, and it is likely that other organizations may have been affected by the same campaign. The fact that the attackers were able to gain unauthorized access to sensitive information and post it online underscores the need for organizations to prioritize cybersecurity and take proactive steps to protect themselves against these types of threats.
The East Western Bank incident also raises questions about the role of nation-state actors in cyberattacks. The Clop ransomware gang is believed to have links to Russia, and the attack on East Western Bank may be seen as part of a broader pattern of Russian cyber aggression. However, it is worth noting that the exact nature and extent of these links are not publicly known, and more research is needed to fully understand the relationship between nation-state actors and cybercrime groups.
The incident has significant implications for the financial sector, which is increasingly reliant on digital technologies and data-driven systems. The fact that a major bank like East Western Bank was affected by the attack highlights the need for financial institutions to prioritize cybersecurity and invest in robust defenses against cyber threats. This includes implementing robust security measures, such as multi-factor authentication and encryption, as well as providing regular training and awareness programs for employees.
The East Western Bank incident also underscores the importance of collaboration and information-sharing between organizations and governments in the face of cyber threats. The fact that multiple organizations were affected by the same campaign highlights the need for greater coordination and cooperation to prevent and respond to these types of attacks. This includes sharing threat intelligence and best practices, as well as working together to develop and implement effective countermeasures.
Overall, the East Western Bank incident is a sobering reminder of the ongoing risks and challenges associated with cyberattacks. The incident highlights the need for organizations to prioritize cybersecurity and take proactive steps to protect themselves against these types of threats. It also underscores the importance of collaboration and information-sharing between organizations and governments in the face of cyber threats.
