July 12, 2023, 2:39 pm | Read time: 4 minutes
As convenient as online banking can be, it presents numerous opportunities for criminals to steal sensitive data. Thousands of bank customers have now fallen victim to a data breach. TECHBOOK explains whether you might be affected and what to do in this case.
Bank customers face challenges in the digital age. Fraudsters use increasingly sophisticated methods to access sensitive data. While vigilant customers can somewhat protect themselves from convincingly real phishing emails or texts, what happens if hackers target the bank or its partners? On Friday, July 7, 2023, Postbank and Comdirect announced that unauthorized individuals had stolen personal data through a data breach. It has now been revealed that customers of ING and Deutsche Bank are also affected.
Also of interest: Everything about online banking
Hack Attack on Moveit Software
The data breach did not occur at the banks themselves but at the account switching service Majorel Germany, with which the financial institutions collaborate. Since 2016, financial institutions have been legally required to assist their (new) customers with account switching. This means the banks take over previous direct debit orders and incoming and outgoing transfers from the old account. This data transfer, which must be completed within a maximum of twelve business days by law, is carried out by Majorel Germany or its subsidiary Kontowechsel24.de. This company uses the Moveit software, which was the weak point exploited by the hackers–and apparently not for the first time.
The Moveit software is used by many international companies across various industries. In June 2023, the Clop extortion group successfully hacked the British payroll service provider Zellis, which also used the Moveit software. Zellis’ affected customers included the BBC, British Airways, Aer Lingus, Boots, the University of Rochester, and the government of the Canadian province of Nova Scotia. The damage caused by security gaps and data breaches in this data transfer software is therefore immense. And now bank customers in Germany are affected as well. However, who is behind the hack remains unknown.
Protect Yourself From Identity Theft With These Tips
3 Quick Tips to Spot Phishing Emails at a Glance
These Data Were Stolen
According to Majorel Germany, the data breach has already been closed. The stolen data includes the first names, last names, and IBANs of customers from Deutsche Bank, Postbank, and Comdirect who used Majorel’s account switching service in 2016, 2017, 2018, and 2020, as a Deutsche Bank spokesperson stated. It seems that data from ING Germany customers, whose account switches date back several years, were also stolen. A “low four-digit number” of ING customers is reportedly affected. However, according to current knowledge, only the data from the statutory account switching assistance is affected, confirmed an ING spokesperson to TECHBOOK, not the “much more frequently used account switching service” at ING. This non-legally required account switching service is an additional offer for new ING customers. However, ING also collaborates with Majorel Germany for this service.
Although the stolen data is personal and sensitive, it is not enough for criminals to empty the account. That’s the good news. However, fraudsters can use it to initiate direct debits. Affected customers should therefore be particularly vigilant in the future and immediately report unauthorized direct debits to their bank and possibly the police. For unauthorized direct debits, customers can reclaim their money from the bank up to 13 months later. This is also good news.
Also of interest: Can you distinguish legitimate emails from phishing?
Beware of Phishing Emails
The bad news is that affected customers are now at a higher risk of fraud. Since Friday, they have been informed by their banks about the data breach. However, potentially affected individuals should be especially cautious if they receive an email from their (supposed) financial institution. With personal data like names and IBANs, fraudsters can create particularly convincing phishing emails. For this reason, affected ING customers will be notified by letter, which should arrive by the end of this week at the latest. If you receive a suspicious email, never click on any links it contains. Instead, try to contact your bank through another medium, such as by phone, to verify the email’s content. Postbank additionally warns on its website about phishing emails that fraudsters send, referencing the IT transition that took place in early 2023.
Although Comdirect is affected by the hack, customers of the parent company Commerzbank do not need to worry, according to current knowledge. Customers of Volks- und Raiffeisenbanken and Sparkassen can also breathe a sigh of relief. These financial institutions claim they do not work with Majorel Germany.