Webster Bank Logo Stamford, CT (image source: Webster Bank (Logos), n.d.))
One-sentence summary:
Webster Bank, through its fraud analytics vendor Guardian Analytics, suffers a 190,000+ victim data breach due to a ransomware attack, resulting in a class-action lawsuit.
Who was involved?
Webster Bank, N.A., 191,563 customers, Guardian Analytics, Inc., a subsidiary of NICE Actimize, Daixin Team, and Lockbit ransomware group.
What was the timeline?
November 27, 2022: Threat actor breaches Guardian Analytics to commence ransomware attack
January 14, 2023: Threat actor exfiltrates data from Guardian Analytics
January 17, 2023: Threat actor’s access to Guardian Analytics ends
January 20, 2023: Guardian Analytics is threatened by threat actors
January 26, 2023: Webster Bank learns Guardian Analytics was under a ransomware attack
January 27, 2023: Webster Bank identifies data on the dark web
January 29, 2023: Guardian Analytics notifies Webster Bank of a data breach due to a ransomware attack
February 10, 2023: Guardian Analytics confirms that Webster Bank data was involved in its attack. Lockbit posts breached data of Webster Bank
April 10, 2023: Webster Bank begins victim notification
April 18, 2023: Class action lawsuit is filed in federal court within New Jersey against Webster Bank and Guardian Analytics
What occurred?
Webster Bank, through its fraud analytics vendor– Guardian Analytics, suffered a data breach impacting over 190,000+ customers (Kessler, 2023a; Webster Bank, 2023). Guardian Analytics was attacked via ransomware by Daixin Team and Lockbit ransomware groups in November 2022, thus impacting Webster Bank data and customers (Kessler, 2023b). Guardian Analytics is also alleged to have not paid any ransom (Kessler, 2023b). The data breached at Webster Bank potentially included: “name, financial account numbers” and “Social Security Number” (Kessler, 2023b). 8 days after notification, a class-action lawsuit was filed against Webster Bank and Guardian Analytics in a New Jersey federal court district (Justia, 2023).
Estimated costs:
Associated incident response costs, breach notification costs, “third-party cybersecurity firm,” 24 months of credit monitoring, 7 day/week call center
Involved laws:
State: Maine: 10 M.R.S.A. § 1346
Root cause:
Vendor data breach: ransomware attack at Guardian Analytics
Lessons learned:
Potential third-party due diligence, pending more information (see disclaimer). Third-party assurance and third-party risk assessments are both critical elements of a third-party relationship. These could potentially uncover a significant liability or risk with a third party, including a potential breach.
Sources:
Justia. (2023, April 18). CHRISTIANI v. GUARDIAN ANALYTICS, INC. et al. Justia Dockets & Filings. Retrieved April 20, 2023, from https://dockets.justia.com/docket/new-jersey/njdce/2:2023cv02158/511335
Kessler, D. (2023a). Data Breach Notifications. In Privacy, Identity Theft and Data Security Breaches. Office of the Maine Attorney General. Retrieved April 19, 2023, from https://apps.web.maine.gov/online/aeviewer/ME/40/a42f73e8-720b-41a2-b892-18181e799668.shtml
Kessler, D. (2023b). Re: Legal Notice of Cyber Incident. In Data Breach Notifications. Privacy, Identity Theft and Data Security Breaches. Retrieved April 19, 2023, from https://apps.web.maine.gov/online/aeviewer/ME/40/a42f73e8-720b-41a2-b892-18181e799668/b98ec910-0efa-43f5-99dc-820d3858eebe/document.html
Webster Bank. (2023). RE: Notice of Data Breach. In Data Breach Notifications (No. B088979). Office of the Maine Attorney General. Retrieved April 19, 2023, from https://apps.web.maine.gov/online/aeviewer/ME/40/a42f73e8-720b-41a2-b892-18181e799668/25a99f73-65d3-4c27-bea6-9440850e90c7/document.html
Webster Bank (Logos). (n.d.). f90b93923c6bde342d78316e1ec63c96.jpeg. Logos Discovery Engine. https://www.logolynx.com/images/logolynx/f9/f90b93923c6bde342d78316e1ec63c96.jpeg
