0% found this document useful (0 votes)
56 views5 pages

Bank Sepah Data Breach Overview 2025

The document details three significant cyberattacks: the Bank Sepah breach in March 2025, which exposed sensitive data of over 40 million users; the Marks & Spencer ransomware attack in April 2025, resulting in a £700 million market value drop; and the Blue Yonder ransomware attack in November 2024, impacting major clients and disrupting supply chain operations. Each incident highlights the severity, attack vectors, and mitigation efforts undertaken by the affected organizations. The document emphasizes the importance of cybersecurity measures in preventing such breaches.

Uploaded by

Sadwik Reddy
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
56 views5 pages

Bank Sepah Data Breach Overview 2025

The document details three significant cyberattacks: the Bank Sepah breach in March 2025, which exposed sensitive data of over 40 million users; the Marks & Spencer ransomware attack in April 2025, resulting in a £700 million market value drop; and the Blue Yonder ransomware attack in November 2024, impacting major clients and disrupting supply chain operations. Each incident highlights the severity, attack vectors, and mitigation efforts undertaken by the affected organizations. The document emphasizes the importance of cybersecurity measures in preventing such breaches.

Uploaded by

Sadwik Reddy
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Name: N SAI SADWIK REDDY

EMP ID : 2629077

Recent Cyberattacks and How They


Happened
Bank Sepah Breach – March 2025

1. Summary
 In March 2025, Iranian state-owned Bank Sepah was breached by a group
called Codebreakers, who claimed to have stolen 12TB of sensitive
customer and military financial data.
 The hackers exposed the financial records of top IRGC officials,
triggering political and public outrage over the stark economic disparities
the leak revealed.

2. Severity
 This breach is one of Iran’s largest known data leaks, compromising
personal and financial details of over 40 million users.
 National security concerns escalated as top government and military
accounts were traced and exposed in the dump.

3. Attack Vectors
 Attackers are believed to have exploited internal misconfigurations or
unpatched vulnerabilities, likely in systems thought to be air-gapped.
 They successfully exfiltrated huge volumes of data and demanded a $42
million ransom, which was not paid.
4. Lines of Code (LOC) Affected
 The attackers likely gained deep access to core banking systems,
impacting modules handling customer records, transaction histories, and
admin panels potentially affecting tens of thousands of LOC.
 Possible exploitation of API endpoints or admin interfaces indicates the
compromise of critical application-level code that governed authentication
or data exports.

5. Mitigation
 Bank Sepah denied the breach, did not acknowledge any ransom
negotiation, and issued threats against publishing the data—a defensive
PR strategy rather than technical mitigation.
 Security analysts recommend a forensic audit of all systems, source code
review, and stronger network segmentation to prevent lateral movement in
future incidents.

6. References
 Wikipedia: Codebreakers Attack on Bank Sepah
 The Cyber Shafarat Report on IRGC Data Leak

Marks & Spencer Cyberattack – April 2025


1. Summary
 In late April 2025, M&S suffered a ransomware attack attributed to the
Scattered Spider group, disrupting online orders, click-and-collect
services, and contactless payments.
 The incident led to the suspension of online orders and recruitment
activities, with over 200 job listings removed from the company's website.
2. Severity
 The attack resulted in a £700 million drop in M&S's market value,
reflecting significant investor concern.
 Operational disruptions affected a substantial portion of M&S's revenue,
particularly from online clothing and home sales.

3. Attack Vectors
 The attackers likely employed social engineering techniques, such as
impersonating IT personnel, to gain unauthorized access.
 The ransomware was deployed via a third-party service provider,
exploiting vulnerabilities in M&S's supply chain.

4. Lines of Code (LOC) Affected


 The ransomware encrypted critical systems, including order processing
and HR platforms, affecting thousands of lines of code.
 The attack disrupted the Sparks rewards program and other customer-
facing applications, indicating widespread codebase impact.

5. Mitigation
 M&S collaborated with the National Crime Agency and the National Cyber
Security Centre to address the breach and enhance cybersecurity measures.
 The company issued public apologies and worked to restore services,
including contactless payments and in-store operations.

6. References
 The Guardian – M&S Cyberattack Linked to Scattered Spider
 The Sun – M&S Cyberattack Update
Blue Yonder Ransomware Attack – November
2024
1. Summary
 On November 21, 2024, supply chain software provider Blue Yonder
experienced a ransomware attack attributed to the Termite group,
disrupting its managed services environment.
 The attack impacted major clients, including Starbucks, Morrisons, and
Sainsbury’s, leading to operational disruptions in employee scheduling
and warehouse management systems.
2. Severity
 The breach affected over 3,000 global customers, causing significant
disruptions in supply chain operations across multiple industries.
 Retailers faced challenges during the critical holiday season, with some
resorting to manual processes to maintain operations.
3. Attack Vectors
 The Termite ransomware group, utilizing a modified version of Babuk
ransomware, infiltrated Blue Yonder's managed services environment.
 The attackers claimed to have exfiltrated 680GB of sensitive data,
including databases, emails, and insurance documents, threatening to leak
the information if ransom demands were not met.

4. Lines of Code (LOC) Affected


 The ransomware likely encrypted critical components of Blue Yonder's
supply chain management software, disrupting services for clients.
 The attack's impact on core functionalities suggests that significant
portions of the application's codebase were compromised.
5. Mitigation
 Blue Yonder collaborated with external cybersecurity firms to implement
defensive and forensic protocols, aiming to restore services and investigate
the breach.
 By early December, the company reported that a majority of affected
customers had resumed normal operations, with ongoing efforts to assist
remaining clients.

6. References
 Help Net Security – Starbucks, grocery stores impacted by Blue Yonder
ransomware attack

Common questions

Powered by AI

The cyberattacks on Bank Sepah and Blue Yonder illustrate critical lessons in mitigation strategies. Bank Sepah’s non-acknowledgment and focus on defensive PR rather than technical solutions suggest the importance of transparent communication alongside technical remediation, such as forensic audits and stronger network segmentation . Conversely, Blue Yonder's approach involved collaboration with cybersecurity firms and forensic protocols to restore services, showing the effectiveness of immediate technical intervention coupled with external expertise . This highlights the need for comprehensive response plans that combine technical action with strategic communication.

The cyberattacks on M&S and Blue Yonder both exploited third-party vulnerabilities, but through different mechanisms. In M&S's case, attackers used a third-party service provider to deploy ransomware, indicating weaknesses in supply chain security . Meanwhile, the Blue Yonder attack involved encryption of critical components, disrupting services for clients through their managed services environment . These incidents highlight the importance of stringent third-party risk management and security assessments as part of a comprehensive cybersecurity strategy.

The economic repercussions of the cyberattack on Bank Sepah were significant, as the exposure of sensitive financial data of IRGC officials highlighted stark economic disparities, fuelling public outrage . This possibly undermined public trust in financial institutions and governmental transparency, indicating broader economic instability and potential for increased societal unrest as a result of perceived injustice and inequality .

The cyberattack on Bank Sepah by the Codebreakers in March 2025 significantly impacted Iran's political environment by publicly exposing the financial records of top IRGC officials. The leak revealed stark economic disparities, triggering political and public outrage. Such exposure heightened national security concerns, indicating vulnerabilities not just in digital infrastructure but also in institutional trust and governance .

Data exfiltration in the Bank Sepah breach had profound implications for national security. The attackers stole 12TB of sensitive data, including military financial records, which could be used for espionage or sabotage purposes . By highlighting vulnerabilities in Iran's financial and administrative systems, it raised concerns over potential manipulation or exploitation of such data by adversarial entities, suggesting a critical need for enhanced cybersecurity protocols to protect national interests and sensitive information .

In the M&S cyberattack, social engineering was a critical tactic, where attackers impersonated IT personnel to gain unauthorized access . This method indicates the vulnerability of human factors within cybersecurity frameworks and suggests a need for enhanced employee training and verification protocols to mitigate such risks in future attacks, emphasizing the importance of holistic security approaches that integrate human awareness with technical defenses.

Forensic protocols played a crucial role in mitigating the impact of the Blue Yonder ransomware attack. By collaborating with external cybersecurity firms, Blue Yonder implemented forensic protocols to restore services and investigate the breach . These protocols help in identifying the root cause, scope, and impact of the attack, allowing for a more targeted and effective response, and serving to prevent future incidents by highlighting security gaps .

The ransomware attack on Blue Yonder severely impacted its clients' operations, notably major retailers like Starbucks, Morrisons, and Sainsbury’s, by disrupting employee scheduling and warehouse management systems . During the critical holiday season, these disruptions forced clients to resort to manual processes to maintain operations, underscoring the dependency on digital systems and the widespread operational impact that a single cyber incident can have on supply chain efficiency .

In the Blue Yonder ransomware attack, the Termite ransomware group employed a modified version of Babuk ransomware to infiltrate their managed services environment. This resulted in major disruptions to employee scheduling and warehouse management systems, affecting supply chain operations across various industries . The breach impacted over 3,000 global customers, showing how critical system vulnerabilities and ransomware deployment can severely affect operational efficiency .

The breach on M&S in April 2025, attributed to the Scattered Spider group, led to a significant £700 million drop in the company's market value due to investor concerns . Operational disruptions were severe, affecting online orders, click-and-collect services, and contactless payments, reflecting substantial revenue loss particularly from online sales . These outcomes demonstrate how cybersecurity incidents can have both direct operational impacts and far-reaching financial repercussions.

You might also like