The CIC incident: when a centralized data store becomes the target

Photo: Markus Spiske / Unsplash
In September 2025, the ShinyHunters group claimed an attack on the National Credit Information Center (CIC) under the State Bank; authorities confirmed personal data was stolen, on the order of 160 million records. It is one of the largest data incidents, and it teaches a clear lesson: the more centralized a data store, the more valuable a target it becomes.
Why centralization raises risk
- One large store is a single point of failure; a successful breach can expose everything.
- Sensitive personal data is highly valuable on the black market, attracting attacks.
- Loose permissions plus a compromised account let attackers move deep easily.
What businesses should take away
- Segregate and use least privilege: don't let one account reach everything.
- Monitor abnormal access and keep full logs for tracing.
- Encrypt sensitive data; avoid hoarding unnecessary data in one place.
- Keep data in controllable infrastructure with the right protections.
Tetra
Manta Security supports permissions, access monitoring and centralized device management — reducing damage when an account or device is compromised. For a review, book a consultation.
Related articles

What Dokploy is: a self-hosted deployment platform for small teams
Dokploy gives you a Heroku-style deployment workflow on your own server. What it does, what sits inside it, who it suits, and the three things newcomers trip over in production.
Read ↗
Securing Dokploy: adding a WAF and IPS on the server itself
A default Dokploy install runs fine but is not safe: Traefik is not a WAF, Docker bypasses UFW, DNS-only domains leak the origin IP. Three gaps and how to close them on your own host.
Read ↗
Vietnam's 2025 Cybersecurity Law: 5-level system classification and what to do
From 1 July 2026, Cybersecurity Law 116/2025 merges two prior laws, codifies "data security" and classifies systems into 5 levels. The new obligations and what to do.
Read ↗Personal Data Protection checklist
Review your business before the law takes effect on 01/01/2026.