Bank confirms data breach impacting 21000+ customers
In a recent development, Western Alliance Bank (WAB), a subsidiary of the Western Alliance Bancorporation in the United States, communicated with over 21,000 customers about a data breach affecting their personal information. The breach, dating back to October 2024, was a result of a compromised third-party vendor’s secure file transfer software employed by WAB.
The security incident came to light when the bank reported it in an SEC filing documented in February. The infiltrators leveraged a zero-day vulnerability that the vendor promptly identified on 27 October 2024. This breach allowed unauthorized entry into a limited number of the bank’s systems, leading to the extraction of sensitive data from its network.
The exfiltration of files went unnoticed until the attackers publicly released some of the stolen data. The breach transpired between 12 October and 24 October 2024. Upon scrutinizing the incident in February 2025, it was ascertained that the filched files comprised essential customer data. These included personally identifiable information such as names, Social Security numbers, birth dates, financial account details, driver’s license numbers, tax identification numbers, and passport information.
Western Alliance reassured its customers that there is no indication of their personal information being misused for fraudulent activities. It emphasized that the breach is not anticipated to have any substantial impact on its operations or business.
In response to the breach, WAB mentioned, “The company will work with clients who may have been impacted and will make appropriate notifications to impacted individuals. Although the company continues to investigate and has not determined the full impact of this incident, at this time the incident has not had a material impact on the Company’s business or operations. The Company does not anticipate any material impact on the Company’s financial condition or results of operations.”
When approached for comments regarding the incident, Western Alliance Bank’s spokesperson was not immediately available for the media.
The Clop ransomware group, notorious for its cyber assaults, took credit for the data breach in January. They included Western Alliance Bank on their leak site as one of the 58 organizations victimized by their breach. The Clop group is recognized for exploiting a zero-day vulnerability in Cleo LexiCom, VLTransfer, and Harmony software.
Cleo, a software utilized by a significant number of global entities, reported a second zero-day vulnerability in December. This vulnerability was also targeted by the Clop ransomware group. The group’s track record includes threatening several companies after exploiting weaknesses in Cleo software.
In conclusion, the breach at Western Alliance Bank shed light on the critical need for heightened cybersecurity measures to safeguard customers’ confidential data from cybercriminals. As organizations continue to grapple with evolving cyber threats, the onus lies on them to reinforce their security protocols and minimize vulnerabilities to mitigate potential risks and data loss.