SILKFIN AGENCY is a database-targeting group known for exfiltrating high-volume personal, agricultural, and financial data.
Analyst brief
SILKFIN AGENCY is a threat actor of unknown type that has claimed responsibility for several large-scale data breaches. This group primarily targets organizations holding vast amounts of sensitive data, such as personal identification (NIC numbers), agricultural records, and financial transaction details, for exfiltration. Their key TTPs appear focused on compromising databases to steal high-volume data, though specific tools or C2 infrastructure details are not provided in the available intelligence. Defenders should heighten monitoring for unauthorized database access and prioritize the protection of high-value personally identifiable information (PII) repositories against exfiltration attempts.
SILKFIN AGENCY
unknown
SILKFIN AGENCY has claimed responsibility for multiple significant data breaches, including the compromise of DimeCuba.com, which exposed over 1 million SMS records and more than 100,000 email records. They also targeted the Sri Lankan Department of Agrarian Development, allegedly compromising the personal and agricultural data of over 1.45 million farmers. Additionally, they claimed a breach of the Siam Cement Group's database. The breaches involved sensitive data such as NIC numbers and transaction details.
What types of sensitive data were stolen in the breaches claimed by SILKFIN AGENCY?+
In the data breaches claimed by SILKFIN AGENCY, high-volume sensitive data such as SMS records, emails, NIC numbers, agricultural data, and financial transaction details were stolen.
Which specific victims were included in SILKFIN AGENCY's data breach operations?+
The breaches claimed by the actor include DimeCuba.com, which exposed over 1 million SMS records, the Sri Lankan Department of Agrarian Development, where data of over 1.45 million farmers was compromised, and the Siam Cement Group's database.