FirstBank: hackers breached system in three years

May 13, 2024
1 min read

TLDR: FirstBank Hires Hackers to Breach Systems

Key Points:

  • FirstBank’s CISO hired hackers to attack its systems over three years to test vulnerabilities.
  • The red team succeeded in compromising the bank’s systems after a three-year exercise.

Article Summary

FirstBank’s chief information security officer, Brenden Smith, shared a case study at the RSA Conference about hiring hackers to attack the bank’s systems. The professional hackers, part of a red team from a company called Randori, attempted to breach FirstBank’s systems over a three-year exercise.

The initial attacks were difficult to detect, as the hackers exploited undiscovered vulnerabilities in the bank’s systems. Despite multiple attempts, the red team did not accomplish their objectives until three years into the exercise when they successfully breached the bank’s systems using an IoT device with a zero-day vulnerability.

Smith emphasized the value of continuous red team exercises in improving cybersecurity measures. The exercise highlighted weaknesses in the bank’s security systems, providing valuable lessons for the institution. Additionally, Smith stressed the importance of realistic simulations to prepare for potential cyberattacks.

Overall, the article underscores the significance of proactive security measures and the benefits of long-term red team exercises in enhancing cybersecurity for financial institutions like FirstBank.

Latest from Blog

Bridging the cyber talent gap: tips for CISOs

TLDR: – Global cyber threats have increased twofold in recent years, leading to a talent gap of nearly 4 million cyber professionals worldwide. – Existing cyber staff are under strain, with vacancies

North Korean hackers pivot to ransomware attacks

TLDR: North Korean hackers from APT45 have shifted from cyber espionage to ransomware attacks APT45 has targeted critical infrastructure and is linked to ransomware families SHATTEREDGLASS and Maui A North Korea-linked threat

Cyber insurance evolves to cover all your online needs

TLDR: Cyber insurance coverage is evolving to help raise security baselines across businesses. Only one-quarter of companies have a standalone cyber insurance policy. In today’s evolving cybersecurity landscape, cyber insurance coverage is