Automatic Bank Services Ltd.
Incident posture
Linked entities
- Victim
- Automatic Bank Services Ltd.
- Threat actors
- 0 actors
- Sources
- 1 source
Timeline
Summary
A cyberattack described as a Distributed Denial of Service (DDoS) event disrupted Israel's national payment clearing system operated by Automatic Bank Services Ltd., preventing credit card transactions from being processed for several hours. The incident was initially reported as a communications malfunction before being officially reclassified as a "simple cyber incident," with the company confirming normal operations had resumed approximately ninety minutes after the disruption began, though some customers continued to report intermittent issues. According to industry experts cited in reporting, the attack involved flooding the payment servers with excessive requests to crash the system, and such tools are typically associated with state-level actors aiming to create a broad cognitive impact rather than steal data or funds. This marked at least the third such service-disruption attack on Israeli clearing services in recent months, following a previous incident at the same organization that lasted three hours and a separate attack on another clearing provider two weeks later.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On February 13, 2025, Automatic Bank Services Ltd., known by its Hebrew acronym Shva, suffered a service disruption that prevented the clearing of credit card transactions in Israel beginning at approximately 11:00 a.m. local time. Shva operates the communications infrastructure that links the various payment clearers responsible for processing credit card transactions across the country. When the malfunction began, the company issued an initial statement indicating that its professional teams were investigating the cause and that updates would be provided as the situation developed. The disruption affected the flow of credit card authorizations and clearances, prompting widespread concern among retailers and consumers who rely on the system for everyday purchases.
About an hour after the disruption began, Shva released an official statement declaring that the national debit card payment system had been operating normally for the past hour and that credit transactions could once again be processed. According to the company, services were restored by 11:30 a.m. However, around 1:00 p.m., several customers continued to report that they were still experiencing problems completing credit transactions, contradicting Shva's announcement that the system had returned to normal operation. Initially, the company characterized the event as a communications malfunction, but later in the afternoon Shva revised its assessment and described the event as a "simple cyber incident."
Investigative reporting by Globes determined that the incident was a distributed denial of service attack, commonly known as a DDoS attack. In this type of attack, many remote servers simultaneously send large volumes of requests to a target server, overwhelming its capacity and rendering it unable to process legitimate transactions. Unlike a data breach or intrusion, a DDoS attack does not involve breaking into systems or stealing information. Instead, it targets service availability, causing operational disruptions that can last several hours. Check Point's chief of staff and head of global communications, Gil Messing, explained that the company's servers were being "bombarded" with an enormous volume of requests, causing them to crash. He noted that the scale of resources required to execute such an attack typically falls within the capabilities of state actors rather than small hacking groups. Messing added that while the clearing system itself was not hacked, the service became effectively inactive, producing noticeable impact on end users. He also pointed out that this was the third such "service-driven attack" targeting clearing services in Israel in recent months, suggesting that adversaries had identified payment clearing infrastructure as a target for creating significant public disruption without needing to breach the underlying systems. Messing stated that Iranian entities had previously been linked to such attacks, though he clarified that this did not necessarily point to Iran in the current case, and that state capabilities could be shared with smaller proxy groups.
Panorays cofounder and chief technology officer Demi Ben-Ari corroborated the assessment that the incident was a DDoS event aimed at reducing service availability. Ben-Ari explained that modern financial services rely heavily on application programming interfaces, or APIs, to facilitate communication between different entities in the payment ecosystem. He noted that an attacker can identify these APIs and overwhelm them with requests, effectively taking them out of service if they are not sufficiently protected. Both experts emphasized that the goal of such an attack appeared to be psychological impact, creating noise and public attention rather than causing economic harm such as data theft or financial fraud.
This was not the first time Shva had experienced a cyber-related disruption. In October 2024, Shva reported difficulties clearing credit card transactions along with communications problems affecting the payment system. The company subsequently confirmed that the outage, which lasted approximately three hours, was caused by a cyberattack. In response to that earlier incident, Shva decided to sever the ability to connect to the Israeli payment system from abroad as a defensive measure. At the time, the company stated that, in its assessment, the incident did not materially affect its revenue. Two weeks after that October incident, a separate disruption was discovered following a cyberattack on HYP's Credit Guard, a clearing solutions provider serving large organizations including supermarket chains, health funds, fashion chains, and public transportation. Because that attack targeted a single company, the resulting damage was less severe, and Shva reported at the time that the national payment system continued to operate normally.
The February 13, 2025 incident unfolded against this backdrop of repeated targeting of Israeli payment infrastructure. The DDoS attack temporarily knocked out credit card clearing capabilities for a window of time during the middle of the day, creating tangible inconvenience for businesses and consumers across the country. Shva's communications during the event evolved over the course of the day, moving from an initial acknowledgment of a malfunction under investigation, to a declaration of restored service, and finally to a public classification of the event as a cyber incident. Customer reports of continued disruption after the company's restoration announcement suggested that either residual effects persisted or that the full scope of the outage extended beyond what Shva initially communicated. The attack did not result in reported theft of data or financial assets, and the company's core clearing infrastructure itself was not breached in a manner that compromised its integrity. The impact was primarily operational and reputational, disrupting the availability of credit card payment services for several hours during a critical business period.
Sources
Sources available to members: 1 source.