The cyberattack took place over the last weekend and forced the bank to shut down a large part of its computer network in response to the incident.
Many services of the bank were disrupted, including online banking, mobile app, and ATM network, many customers crowded the Pichincha bank branches that remained open the days after the cyber attack. The Banco Pichincha has about 1.5 million clients for a portfolio of $1.5 billion.
The bank issued a statement on Monday to inform the customers about the cyber attack, it also added to have “identified a cybersecurity incident in our systems that has partially disabled our services.”
The main bank shareholder, Fidel Egas, tweeted that “We are doing the impossible. They want to blame us for something in which we are the victims.”
The authorities, including the Superintendency of Banks, are investigating the incident.
The public information about the attack suggests that the bank was the victim of a ransomware attack, sources in the cybersecurity industry confirmed it to BleepingComputer.
This is the second attack suffered by the Ecuador bank this year, in February a cybercrime group called ‘Hotarus Corp’ has breached the Banco Pichincha, and the local Ministry of Finance (the Ministerio de Economía y Finanzas de Ecuador). The group claimed to have also stolen data from the Banco Pichincha bank and infected a system at Ministry of Finance using for training purposes with PHP-based ransomware.
An alleged member of the @HotarusCorp leaked on a hacking forum a link to a file containing 6500 records (Email, Identity Card numbers, and passwords) that claims to Ministry of Finance.
Follow me on Twitter: @securityaffairs and Facebook
| [adrotate banner=”9″] | [adrotate banner=”12″] |
(SecurityAffairs – hacking, Banco Pichincha)
[adrotate banner=”5″]
[adrotate banner=”13″]
A new round of the weekly Security Affairs newsletter has arrived! Every week, the best…
Fintech firm Figure confirmed a data breach after hackers used social engineering to trick an…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a flaw in BeyondTrust RS and…
A new alleged Russia-linked APT group targeted Ukrainian defense, government, and energy groups, with CANFAIL…
A new threat actor, UAT-9921, uses the modular VoidLink framework to target technology and financial…
Attackers quickly targeted BeyondTrust flaw CVE-2026-1731 after a PoC was released, enabling unauthenticated remote code…
This website uses cookies.