Ransomware

LockBit 3.0 Claims Responsibility for Attack on Banco de Venezuela, S.A.

In April 2023, Banco de Venezuela, S.A. was the target of a ransomware attack attributed to the Lockbit 3.0 group. The threat actors added the bank to their dark web leak site on April 19, 2023, threatening to publish stolen confidential information—including Venezuelan ID cards, tax documents (RIF), INCES certificates, and corporate financial records— by May 10, 2023, unless a ransom in cryptocurrency was paid. In response to the incident, the bank issued a statement assuring its customers that its platforms and electronic channels were operating normally with full integrity and security, although it neither explicitly confirmed nor denied the data exfiltration.

Overview

Missing evidence

There is no publicly available forensic validation of the complete set of files.Banco de Venezuela denied the initial claim and did not confirm the subsequent leak.

Impact details

7,000 Exposed records

LockBit added Banco de Venezuela to its list, and the published files were subsequently reviewed. The bank denied that its platform had been compromised in April; the publication of the data was later reported by the media.

identity documentstax documentsinsurance claimsinternal bank documents

Classification & severity

Category
Malicious code
Subtype
Ransomware
Confidence
High

Ransomware/extortion listing or leak-site claim; the extent of the impact varies depending on public validation.

Severity assessment

High
Information impact
Sensitive personal data
Affected scope
Multiple users
Critical service
Potential
Public confidence
Moderate
Recoverability
Extended

Ransomware/extortion claim; the confidence level and severity are higher when the media has reported that files have been published.

Data exfiltration· Confirmed Confidentiality

Timeline

Claim

Lockbit 3.0 listed Banco de Venezuela, S.A. as an alleged victim.

Evidence & sources

4 sources