CSIDB logo
Incident

Postbank

Incident posture

Attack window
May 2023
Location
Germany
Status
Historical
CIA posture
Available to members
Updated
2025-12-20 00:00

Linked entities

Victim
Postbank
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
May 2023
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A cyberattack targeting Majorel, a service provider handling account switching processes, resulted in the theft of over 144,000 customer datasets, with Postbank and Deutsche Bank identified as the most severely impacted institutions. The compromised data included sensitive customer information such as names and account numbers, which subsequently appeared for sale on darknet platforms. The incident exposed vulnerabilities in third-party vendor security and led to unauthorized access to financial records across multiple banking clients.

Motives

Detailed motive labels are available to members.

2 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

In early 2023, a cybersecurity incident occurred involving Majorel, a service provider specializing in account switching services for financial institutions. Attackers breached Majorel's systems, resulting in the theft of sensitive customer data. The compromised information included customer names and linked bank account numbers, which subsequently appeared for sale on darknet platforms. Postbank emerged as the most severely impacted institution, with Deutsche Bank also affected through their shared reliance on Majorel's services. The breach exposed vulnerabilities in third-party vendor security practices, though the specific attack vector used by the hackers remained unspecified in initial reports. The incident highlighted risks associated with outsourcing critical financial operations to external processors.

On May 31, 2023, subsequent investigations revealed the full scale of the data theft, confirming that attackers had exfiltrated more than 144,000 customer datasets. Postbank bore the brunt of the compromise, though the exact distribution of affected customers across different banks wasn't fully detailed. The exposure of account numbers and personal identifiers created immediate risks of financial fraud and unauthorized transactions for impacted individuals. No public information indicated whether the stolen data included additional sensitive elements beyond names and account details. The incident prompted scrutiny of Majorel's security protocols and raised concerns about supply chain vulnerabilities in banking operations, particularly regarding lesser-known service providers handling sensitive customer information.

Sources

Sources available to members: 1 source.

CSIDB