Skip to content
Blog

The CIC incident: when a centralized data store becomes the target

Trần Quốc BảoTrần Quốc Bảo · Cybersecurity engineer··1 min read
The CIC incident: when a centralized data store becomes the target

Photo: Markus Spiske / Unsplash

In September 2025, the ShinyHunters group claimed an attack on the National Credit Information Center (CIC) under the State Bank; authorities confirmed personal data was stolen, on the order of 160 million records. It is one of the largest data incidents, and it teaches a clear lesson: the more centralized a data store, the more valuable a target it becomes.

Why centralization raises risk

  • One large store is a single point of failure; a successful breach can expose everything.
  • Sensitive personal data is highly valuable on the black market, attracting attacks.
  • Loose permissions plus a compromised account let attackers move deep easily.

What businesses should take away

  • Segregate and use least privilege: don't let one account reach everything.
  • Monitor abnormal access and keep full logs for tracing.
  • Encrypt sensitive data; avoid hoarding unnecessary data in one place.
  • Keep data in controllable infrastructure with the right protections.

Tetra

Manta Security supports permissions, access monitoring and centralized device management — reducing damage when an account or device is compromised. For a review, book a consultation.

Related articles

Free resource

Personal Data Protection checklist

Review your business before the law takes effect on 01/01/2026.

Get the checklist