DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

HSBC insider breach: Fallout continues for private banking clients and the bank

Posted on February 9, 2015 by Dissent

The HSBC data theft by their former employee Hervé Falciani is finally getting a lot of mainstream media attention here, with 60 Minutes doing a segment on Falciani last night (video).

The computer files, which Falciani shopped to a number of governments, reveal that HSBC, one of the largest banks in the world, profited from its private banking arm that did business with “arms dealers who channeled mortar bombs to child soldiers in Africa, bag men for Third World dictators, traffickers in blood diamonds and other international outlaws,” according to the International Consortium of Investigative Journalists.

If the leak and its implications are news to you, you haven’t been reading this blog for long, as I’ve been covering this insider breach and its consequences for the bank and tax evaders since 2009.  Searching this blog for “HSBC Falciani” will take you to some of the previous coverage. Or head on over to the International Consortium of Investigative Journalists to take a look at their project on these leaks and their backgrounder on Falciani. The Guardian also running a big piece on the breach and resulting investigations.

Expect to see a lot of pieces as individual athletes, politicians, and celebrities make headlines as their attempts to evade taxes get picked up by the media.  But don’t lose sight of the bigger issues. Did HSBC engage in felonious behavior under our laws, and if so, what will happen to the bank? Did HSBC make privacy and data security assurances to its private banking clients that it failed to keep? And when we think about damage from external threats vs. internal threats, how do we calculate the financial damage/injury from this one? While the JPMorgan Chase hack made lots of headlines this summer (and rightfully so), the HSBC breach may stand as one of the worse, if not the worst, breach ever in the financial sector, even though the number affected is not as great as some other breaches.


Related:

  • PowerSchool commits to strengthened breach measures following engagement with the Privacy Commissioner of Canada
  • Hungarian police arrest suspect in cyberattacks on independent media
  • Two more entities have folded after ransomware attacks
  • British institutions to be banned from paying ransoms to Russian hackers
  • Data breach feared after cyberattack on AMEOS hospitals in Germany
  • Microsoft Releases Urgent Patch for SharePoint RCE Flaw Exploited in Ongoing Cyber Attacks
Category: Breach IncidentsFinancial SectorInsiderNon-U.S.Of NoteTheft

Post navigation

← Big cyberattacks crippling private cyberinsurance firms
Uncovering Security Flaws in Digital Education Products for Schoolchildren →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Canadian cybercriminal sentenced to a year in prison for NFT theft scheme
  • Oops! Catasauqua employees’ Social Security numbers, other data accidentally sent to government watchdog group
  • EU-wide Breach Notification Template on the Horizon
  • Sex toy maker Lovense caught leaking users’ email addresses and exposing accounts to takeovers
  • Hackers wipe out Rs 384 crore from Bengaluru cryptocurrency firm Neblio Technologies; firm says inside job
  • Intelligence cyberattack on Crimea. Documents confirming abduction of children from Ukraine found
  • Seminole County Schools recovers money taken by hackers
  • Minnesota National Guard deployed; St. Paul declares state of emergency in response to cyberattack
  • Scattered Spider Hijacks VMware ESXi to Deploy Ransomware on Critical U.S. Infrastructure
  • Hacker group “Silent Crow” claims responsibility for cyberattack on Russia’s Aeroflot

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Attorney General James Takes Action to Protect Sensitive Personal Information of Tens of Millions of People
  • Searches of Your Private Data in the Cloud Amount to Illicit State Action
  • How a Tax Subpoena in Ohio Tests European Privacy Law
  • Cambodia moves to enact comprehensive data privacy law
  • White House ordered to restore Medicaid funding to Planned Parenthood clinics
  • California Attorney General Announces $1.55M CCPA Settlement with Healthline.com
  • Canada’s Bill C-2 Opens the Floodgates to U.S. Surveillance

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.