2023 MOVEit vendor breach — account switching service
Data compromised
Customer names, account numbers, IBANs
Technical writeup
Deutsche Bank customer data exposed via breach at external service provider Majorel Deutschland, which operated the bank's account switching service. Clop ransomware group exploited MOVEit Transfer vulnerability (CVE-2023-34362). Affected customers who used account switching in 2016–2018 and 2020. Bank's own systems not compromised. Deutsche Bank extended unauthorized direct debit return period to 13 months.
Root cause
Third-party MOVEit vulnerability; Majorel vendor compromise