BreachLaboratory is a cybercrime group known for stealing and selling financial customer data on underground forums.
Analyst brief
BreachLaboratory is a cybercrime group focused on stealing and selling financial and identity data from organizations, primarily targeting financial institutions like banks and insurance companies. Their key TTPs include exfiltrating structured datasets such as CSV files and SQL dumps, and selling them on underground forums while emphasizing the validity of sensitive details including customer names, account information, and SWIFT codes. This actor's monetization approach indicates a high risk of downstream fraud enablement. Defenders should monitor underground forums for leaked data, enhance monitoring for unauthorized database access, and prioritize protection of customer financial records against potential fraud.
BreachLaboratory
unknown
BreachLaboratory is a cybercrime actor that specializes in the extraction and sale of sensitive financial and identity datasets from various organizations. They have claimed to exfiltrate approximately 950,000 records from Grupo Catalana Occidente and over 18,000 records from Bank Mandiri, with data including customer names, account details, and SWIFT codes. The actor operates on underground forums, selling structured datasets such as CSV files and SQL dumps, and emphasizes the validity and financial utility of the data. Their activities indicate a focus on monetization through direct database sales and potential downstream fraud enablement.