International banking giant Santander has disclosed that customer and staff data has been breached after a third-party provider was compromised.
In a statement published on 14 May, the bank said that it had recently become aware of unauthorised access to a Santander database, which was hosted by a third-party.
So far, the company revealed that data from customers of Santander Chile, Spain and Uruguay, as well as some current and former Santander employees of the group had been accessed.
Customer data in all other Santander markers and businesses are not affected, according to the banking group.
No transactional data, nor any credentials that would allow transactions to take place on accounts are contained in the database, including online banking details and passwords.
The bank’s operations and systems are not affected, so customers can continue to transact securely.
After becoming aware of the breach, the Spanish bank implemented measures to mitigate the impact of the incident immediately, including blocking the compromised access to the database and establishing additional fraud prevention controls to protect affected customers.
Santander has encouraged all customers to stay vigilant, and to always verify information they receive, as well as only contact the bank through official channels.
Recommended reading
- Report: Vulnerability Exploitation Surge Endangers Cybersecurity
- ISC2 Study Exposes Gender Disparities in Cybersecurity Workforce
- Cyber Leaders Reveal Compliance and Boardroom Struggles
The bank has also informed customers told customers that it will never ask customers for codes, OTPs, or passwords.
Suspicious emails and messages should be reported to the bank directly, and online banking should never be accessed from suspicious emails or unsolicited emails.
Further, customers are advised to never ignore security notifications or alerts from Santander related to their accounts.





