CSIDB logo
Incident

Banco Santander

Incident posture

Attack window
May 2024
Location
Spain
Status
Historical
CIA posture
Available to members
Updated
2026-06-19 09:54

Linked entities

Victim
Banco Santander
Threat actors
0 actors
Sources
2 sources

Timeline

Occurred
May 2024
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Banco Santander reported an unauthorized access to a database hosted by an external provider that contained customer information from Spain, Chile and Uruguay as well as data on all current and some former employees. The bank confirmed that no transactional details, login credentials or internet banking passwords were exposed and that its core systems and operations remain unaffected. Upon discovery, it blocked the access, strengthened fraud‑prevention measures, notified regulators and law‑enforcement agencies, and began proactively informing the affected customers and staff.

Motives

Detailed motive labels are available to members.

3 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

Grupo Santander reported that it recently became aware of an unauthorized access to a database belonging to the entity that is hosted by an external provider. Upon discovery, the bank immediately blocked access to the affected database and strengthened its fraud‑prevention measures to protect customers. An investigation was launched to determine the nature and extent of the breach. The bank stated that these steps were taken without delay to address the incident.

The investigation confirmed that the compromised database contained personal information of customers in Spain, Chile and Uruguay, as well as data relating to all current employees and some former employees of the Santander group. No customer data from other markets or business lines were affected. The bank emphasized that the database did not hold transactional data, access credentials, or internet‑banking passwords that could be used to operate accounts. Consequently, Santander’s operational systems and banking services remained unaffected and customers could continue to conduct transactions safely. The bank noted that without transactional data or access credentials, the information accessed could not be used to operate accounts.

Santander notified the relevant regulators and law‑enforcement authorities in a timely manner and indicated that it would continue to cooperate with them. The bank also communicated directly and proactively with the customers and employees whose information had been accessed. In its public statement, Santander expressed regret over the incident and reiterated that its processes and systems were not impaired. The bank concluded by affirming that affected individuals were being informed and that remedial actions remained in place.

Sources

Sources available to members: 2 sources.

CSIDB