Topics

Latest

AI

Amazon

Article image

Image Credits:Bryce Durbin / TechCrunch

Apps

Biotech & Health

Climate

an illustration of a passport

Image Credits:Bryce Durbin / TechCrunch

Cloud Computing

Commerce

Crypto

endeavor

EVs

Fintech

Fundraising

gizmo

stake

Google

Government & Policy

Hardware

Instagram

Layoffs

Media & Entertainment

Meta

Microsoft

Privacy

Robotics

Security

societal

Space

startup

TikTok

Transportation

speculation

More from TechCrunch

result

Startup Battlefield

StrictlyVC

newssheet

Podcasts

television

Partner Content

TechCrunch Brand Studio

Crunchboard

reach Us

The stolen database contains 5.3 million records

A financially motivated criminal hacking group says it has stolen a confidential database stop millions of records that companies use for screening possible customers for golf links to sanctions and financial criminal offense .

The hackers , which call themselves GhostR , said they stole 5.3 million track record from the World - Check screening database in March and are threaten to release the data online .

human race - Check is a screening database used for “ know your client ” checks ( or KYC ) , allow for troupe to determine if prospective client are high-pitched risk or potential criminals , such as the great unwashed with links to money laundering or who are under political science authority . The hackers tell apart TechCrunch that they stole the data from a Singapore - based firm with access to the World - Check database , but did not name the firm .

A portion of the steal data , which the hackers divvy up with TechCrunch , includes individuals who were sanctioned as lately as this year .

Simon Henrick , a interpreter for the London Stock Exchange Group , which defend the database , tell apart TechCrunch : “ This was not a surety breach of LSEG / our systems . The incident involves a third political party ’s data set , which include a copy of the World - Check information filing cabinet . This was illicitly obtained from the third company ’s organisation . We are arbitrate with the affect third party , to guarantee our data is protected and ensuring that any appropriate authorities are advise . ”

LSEG did not name the third - party company , but did not dispute the amount of information stolen .

The portion of stolen data see by TechCrunch contains records on yard of hoi polloi , including current and former government functionary , diplomats , and individual companies whose leaders are considered “ politically disclose mass , ” who are at a high risk of exposure of affaire in corruption or bribery . The list also contain individual charge of intimacy in organized crime , suspected terrorist , intelligence private detective anda European spyware trafficker .

Join us at TechCrunch Sessions: AI

Exhibit at TechCrunch Sessions: AI

The data point diverge by record . The database contain name , recommendation numbers , Social Security numbers , on-line crypto account identifier and savings bank story numbers , and more .

World - Check is currently own by the London Stock Exchange Group following a $ 27 billion deal to buy financial datum provider Refinitiv in 2021 . LSEG gather up information from public generator , admit sanctions lists , government sources and news program outlets , then provides the database as a subscription to company for conduct customer due diligence .

But in camera run database , like World - Check , are know to contain errors that canaffect entirely innocent peoplewith no link or connexion to crime but whose information is stash away in these databases .

In 2016 , an older transcript of the World - Check databaseleaked onlinefollowing a security measure reverting at a third - company company with access to the data , include a former advisor to the U.K. government that World - Check had utilise a “ terrorism ” recording label to his name . Banking giant HSBCshut down banking company accountsbelonging to several prominent British Muslims after the World - Check database branded them with “ terrorism ” tag .

A spokesperson for the U.K. ’s data security authority , the Information Commissioner ’s Office , did not directly annotate on the breach .

To contact this reporter , get in tactual sensation on Signal and WhatsApp at +1 646 - 755 - 8849 , orby electronic mail . you’re able to also send files and document viaSecureDrop .