Digital-first bank Hatch Bank confirms data breach after hackers exploit zero-day to steal 140,000 customer Social Security numbers.

Continue reading
Hatch Bank, a digital-first bank that provides fintech companies with infrastructure for their own branded credit cards, has disclosed a data breach that resulted in the theft of over 140,000 customer Social Security numbers. The bank confirmed that hackers exploited a zero-day vulnerability in the internal file transfer software of Fortra, a company that provides GoAnywhere software for secure file transfers.
The vulnerability in Fortra’s GoAnywhere software was first reported on February 2, when security journalist Brian Krebs shared details of the tech company's security advisory that was previously hidden behind a login prompt. Meanwhile, the infamous Clop ransomware group has claimed responsibility for exploiting this zero-day vulnerability tracked as CVE-2023-0669 to steal data from over 130 organizations. Hatch Bank became the second known victim after Community Health Systems, one of the largest healthcare providers in the United States, disclosed falling victim to the same zero-day vulnerability.
According to the data breach notification filed with Maine's attorney general, the attackers exploited the vulnerability in Hatch Bank's GoAnywhere system to steal the names and Social Security numbers of nearly 140,000 customers, including 630 individuals based in Maine. Hatch Bank reported that Fortra learned of the vulnerability in its GoAnywhere software on January 29 but did not notify the bank until February 3, one day after Krebs reported on the security flaw. Fortra did not respond to TechCrunch's inquiries.
The hackers had unauthorized access to Hatch Bank's account from January 30 to January 31. After the breach, the bank immediately took steps to secure its files and initiated a comprehensive review of relevant files to determine the extent of the information that may have been impacted. Hatch Bank has also informed federal law enforcement.
The bank offers those affected by the breach access to free credit monitoring services and is working to implement additional safeguards internally. The bank has also started providing cybersecurity training to its employees. Jer Wood, president of Hatch Bank, declined to answer TechCrunch's questions.
The full extent of the fallout from the GoAnywhere vulnerability is unknown, but Clop's claims suggest that many more victims have yet to come forward. Security experts have compared the flaw to an earlier zero-day flaw affecting Accellion's legacy file transfer appliance (FTA), which was used to compromise a number of organizations, including Qualys, Shell, the University of Colorado, Kroger, and Morgan Stanley.

Millions of driver's license records were exposed in a massive data breach, raising identity theft risks and highlighting critical data security failures.