icicibank.com Listed by apt73 Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
icicibank.com was listed by the apt73 ransomware group on January 21, 2025, with an undisclosed number of internal files reported as exfiltrated. Individuals who may have had dealings with the bank should review their accounts and consider any steps recommended by icicibank.com.
Ransomware groups have intensified pressure on financial institutions worldwide, using leak-site listings to amplify leverage after claimed data theft. In this climate, the appearance of a major Indian bank on such a site draws attention because banking systems hold concentrated personal and financial records that can be abused long after an initial intrusion.
On 21 January 2025, icicibank.com was listed by the apt73 ransomware group. Public reporting describes the event as a ransomware attack in which internal files were allegedly exfiltrated. The number of people affected remains unknown, and further technical detail has not been released. The listing itself is a claim by the group; independent confirmation of the full scope has not been provided in available records.
Inside the incident
Available information is limited to the leak-site listing and a brief characterisation of the event. According to the reported summary, the organisation is a banking entity in India, and the incident is framed as a ransomware attack involving the exfiltration of internal files. No public figure has been given for the volume of data taken, the precise date of intrusion, the initial access method, or the number of individuals whose information may be involved. Timing beyond the 21 January 2025 reporting date, the scale of any encryption, and any ransom demand remain undisclosed. The facts state only that internal files were claimed to have been removed; they do not confirm whether systems were restored, whether negotiations occurred, or whether the data has been published beyond the listing itself.
The group behind it: apt73
apt73 is identified in the listing as a ransomware group. Groups operating under this model commonly employ double-extortion tactics: they encrypt systems while also copying data, then threaten to release the material on a dedicated leak site if payment is not made. Public knowledge of such actors indicates they typically target organisations holding valuable records, advertise victims to increase pressure, and sometimes auction or drip-release files. Prior activity attributed to similarly named ransomware operations has included claims against enterprises across multiple sectors, though specifics of earlier campaigns are not tied to this particular listing. In the present case, the group claims to have listed icicibank.com after an attack that involved exfiltration of internal files. No further statements from the group about this victim appear in the available facts, and the listing should be treated as an unverified claim unless corroborated by the organisation or independent investigators.
About icicibank.com
icicibank.com is the online presence of ICICI Bank, one of India’s largest private-sector banks. Institutions of this type provide retail and corporate banking, credit cards, loans, investment products and digital payment services to millions of customers. They routinely process and store account details, transaction histories, identity documents, contact information and authentication credentials. A breach affecting such an organisation is consequential because the data held is both sensitive and reusable: financial records can enable fraud, and identity information can support long-term impersonation or further targeting. Even when only internal files are named, the potential reach extends to employees, partners and customers whose records may reside in those systems.
What data was at risk
The facts state that internal files were exfiltrated in a ransomware attack. No more granular inventory—such as customer databases, employee records, source code or specific document categories—has been disclosed. Exact contents therefore remain unconfirmed. Organisations in the banking sector typically hold customer names, addresses, phone numbers, email addresses, account numbers, transaction logs, Know-Your-Customer documentation, credit information and internal operational files. Whether any of those categories were among the files claimed by apt73 is not established by the public record. Readers should treat the exposure as limited to the description given: internal files, with no verified count of affected individuals.
What's at stake
For individuals, the practical risks centre on financial fraud and identity misuse. Stolen banking-related data can be used to attempt unauthorised transfers, open new accounts, or craft convincing phishing messages that reference real account activity. Even internal files that appear administrative can contain enough personal detail to support social-engineering attacks. For the organisation, consequences include potential regulatory scrutiny under Indian data-protection and banking rules, costs of investigation and remediation, and erosion of customer trust. Because the number of people affected is unknown and the precise data types unconfirmed, the full extent of downstream harm cannot yet be measured; the risk remains real but bounded by the limited public facts.
What to do if you're exposed
If you hold an account or other relationship with the bank, monitor statements and transaction alerts for unfamiliar activity and enable any available multi-factor authentication. Consider changing online banking passwords and security questions, and be cautious of unsolicited messages that reference the incident or request credentials. Report suspicious transactions to the bank promptly through official channels. Because breach data often circulates for months or years, it is also useful to check whether your email address has already appeared in known breach collections; free exposure-scan tools can provide an initial indication without requiring payment. Stay alert to official updates from the bank rather than relying solely on third-party claims.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
mistralsolutions.com Listed by apt73 Ransomware GroupIndia car owners Listed by apt73 Ransomware Grouprealtaxcanada.com Listed by apt73 Ransomware Groupfederalbank.co.in (PART1) Listed by apt73 Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the icicibank.com Listed by apt73 Ransomware Group →
Publicly posted by apt73 — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.