The new ransomware playbook: Why ASEAN banks are losing the disclosure war
Late last year, a regional bank in Southeast Asia received an unusual email. Not from the attackers, but from their regulator. The supervisor had received an anonymous tip claiming the bank had suffered a major data breach two weeks earlier, with sample customer records attached as proof. The breach had happened. The bank had not […] The post The new ransomware playbook: Why ASEAN banks are…
In Southeast Asia, a new ransomware playbook is emerging, causing banks to lose control over disclosure decisions. In a recent incident, an anonymous tip led a regional bank regulator to discover a data breach that had already occurred. The attackers demanded payment in cryptocurrency to prevent the release of customer records and other sensitive information.
ASEAN banks have traditionally relied on an outdated ransomware playbook, which involved offline backups, phishing training, and network segmentation. However, recent shifts in ransomware tactics have made this approach ineffective. Modern ransomware operators now prioritize data exfiltration before encryption, and they employ three forms of extortion: decryption, denial-of-service attacks, and enterprise client contact.
Additionally, attackers are leveraging regulatory obligations as leverage to force disclosure. Three factors in ASEAN - outsourced perimeters, disclosure rule asymmetry, and supervisor capacity - make banks particularly vulnerable to this new approach. Some institutions are taking steps to address these issues. They are creating pre-staged disclosure plans, conducting adversary-aware tabletop exercises, and improving vendor risk visibility.
To further reduce the gap, banks should update their incident response playbooks to account for forced disclosure, harden the supervisory channel by establishing a standardized process for attacker-initiated disclosures, and strengthen relationships with vendors that hold their data.
Written by urgent.news from e27's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.