Cyber Incident Victim: Banco Santander
Date:
May 2024
Location:
Spain
Summary
Banco Santander reported an unauthorized access to a database hosted by an external provider that contained customer information from Spain, Chile and Uruguay as well as data on all current and some former employees. The bank confirmed that no transactional details, login credentials or internet banking passwords were exposed and that its core systems and operations remain unaffected. Upon discovery, it blocked the access, strengthened fraud‑prevention measures, notified regulators and law‑enforcement agencies, and began proactively informing the affected customers and staff.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 3 motives | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
Grupo Santander reported that it recently became aware of an unauthorized access to a database belonging to the entity that is hosted by an external provider. Upon discovery, the bank immediately blocked access to the affected database and strengthened its fraud‑prevention measures to protect customers. An investigation was launched to determine the nature and extent of the breach. The bank stated that these steps were taken without delay to address the incident.

The investigation confirmed that the compromised database contained personal information of customers in Spain, Chile and Uruguay, as well as data relating to all current employees and some former employees of the Santander group. No customer data from other markets or business lines were affected. The bank emphasized that the database did not hold transactional data, access credentials, or internet‑banking passwords that could be used to operate accounts. Consequently, Santander’s operational systems and banking services remained unaffected and customers could continue to conduct transactions safely. The bank noted that without transactional data or access credentials, the information accessed could not be used to operate accounts.
Santander notified the relevant regulators and law‑enforcement authorities in a timely manner and indicated that it would continue to cooperate with them. The bank also communicated directly and proactively with the customers and employees whose information had been accessed. In its public statement, Santander expressed regret over the incident and reiterated that its processes and systems were not impaired. The bank concluded by affirming that affected individuals were being informed and that remedial actions remained in place.
