Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Bankinter

Bankinter Vendor Cyber Rating & Cyber Score

bankinter.com

Bankinter somos una marca de referencia dentro de la banca española por Internet. Una parte fundamental de nuestra estrategia es la calidad en el Servicio al cliente y la Innovación. El espíritu viene definido por nuestros valores de agilidad, entusiasmo, integridad y originalidad. Desde bankinter.com se ofrece una amplia gama de productos y servicios financieros, además de asesoramiento a clientes, agregadores, simuladores de productos y una gran variedad de servicios de valor añadido. La plantilla de Bankinter es una plantilla joven, formada, ágil, flexible, capaz de adaptarse rápidamente a los cambios tanto tecnológicos como del mercado. Además, un porcentaje muy elevado de la misma es accionista del Banco, lo que la convierte en


Bankinter A.I CyberSecurity Scoring

Bankinter
Company Information
Website:http://www.bankinter.com
Employees number:6,439
Number of followers:114,802
NAICS:52211
Industry Type:Banking
Homepage:bankinter.com
Bankinter Risk Score (AI oriented)
Between 700 and 749
logo
BankinterBanking
Updated:
01/05/2026
728/1000
Moderate
Ba
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Bankinter Global Score (TPRM)
xxxx
logo
BankinterBanking
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Bankinter
BankinterModerate
Current Score
728Ba (MODERATE)
01000
1 incidents
0 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
736Before Incident
JULY 2026
733Before Incident
JUNE 2026
731Before Incident
MAY 2026
728Before Incident
APRIL 2026
728Before Incident
MARCH 2026
727Before Incident
FEBRUARY 2026
725Before Incident
JANUARY 2026
724Before Incident
DECEMBER 2025
723Before Incident
NOVEMBER 2025
721Before Incident
OCTOBER 2025
720Before Incident
SEPTEMBER 2025
719Before Incident
MARCH 2024
789Before Incident
Breach
23 Mar 2024Bankinter
Bankinter and EVO Banco: Bankinter fined €240K for EVO Banco data breach exposing 1.27M records

Spain’s AEPD Fines Bankinter €240,000 Over 2024 EVO Banco Data Breach

688After Incident
CRITICAL-101
EVOBAN1777652813
Spain’s AEPD Fines Bankinter €240,000 Over 2024 EVO Banco Data Breach Spain’s data protection authority (AEPD) has concluded its investigation into a 2024 cyberattack on EVO Banco, imposing a €240,000 fine on Bankinter after the lender absorbed EVO Banco through a merger. The breach, which exposed sensitive personal and financial data of over 1.27 million individuals, stemmed from an API vulnerability introduced during a system migration in February 2024. The flaw, approved through EVO Banco’s internal change management process, removed access controls on an API used in customer onboarding, allowing unauthenticated queries to retrieve data. Between 23 and 27 March 2024, the vulnerable endpoint processed 5.47 million requests, with 1.27 million successfully accessing personal records. Exposed data included names, national identity numbers, IBANs, employment details, VAT declarations, and income levels far exceeding the bank’s initial characterization of the breach as limited to basic identifying information. EVO Banco only detected the incident on 8 April 2024 after a third-party cybercrime monitoring service flagged a Dark Web post advertising a database of 1.3 million customers. The attacker, who joined the forum weeks earlier with minimal reputation, later demanded a ransom, publishing data for 958 clients and four employees when EVO Banco refused to pay. The bank filed a police report on 22 April 2024, though forensic analysis could not confirm whether the full dataset was exfiltrated. The AEPD’s investigation identified three critical security failures: the API’s lack of authorization checks, unencrypted personal data, and a change management process that failed to test for access control vulnerabilities. While EVO Banco initially classified the breach as low-risk and declined to notify affected individuals, the AEPD intervened on 18 April 2024, ordering mandatory disclosures under GDPR Article 34. The proposed fine of €400,000 was reduced to €240,000 after Bankinter acknowledged liability and paid voluntarily in November 2025. The AEPD cited aggravating factors, including the scale of exposed financial and identity data, but applied mitigations due to the merger, which transferred legal responsibility to Bankinter following EVO Banco’s deregistration in April 2025. The case underscores the risks of inadequate API security and the limitations of internal risk assessments when financial data is involved. It also highlights the AEPD’s enforcement focus on data processing governance, with recent fines against Informa D&B (€1.8M), FC Barcelona (€500K), and Yoti (€950K) reinforcing its scrutiny across sectors.
INCIDENT DETAILS -
TYPE
Data Breach
MOTIVATION
Financial gain (ransom demand)
IMPACT
Financial Loss: €240,000 fineData Compromised: Personal and financial data of over 1.27 million individualsSystems Affected: Customer onboarding APIOperational Impact: Mandatory disclosures under GDPR Article 34, police report filedBrand Reputation Impact: Yes (EVO Banco and Bankinter)Legal Liabilities: GDPR violation, AEPD fineIdentity Theft Risk: High (exposed national identity numbers, IBANs, employment details, VAT declarations, income levels)Payment Information Risk: High (exposed IBANs)
DATA BREACH
NamesNational identity numbersIBANsEmployment detailsVAT declarationsIncome levelsNumber Of Records Exposed: 1.27 millionSensitivity Of Data: High (financial and personally identifiable information)Data Exfiltration: Unconfirmed (attacker published data for 958 clients and 4 employees)Data Encryption: No (unencrypted personal data)Personally Identifiable Information: Yes (national identity numbers, names, employment details, etc.)

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Bankinter ?
?
What was Bankinter's A.I Rankiteo Cyber Score in July 2026 ?
?
What was Bankinter's A.I Rankiteo Cyber Score in June 2026 ?
?
What was Bankinter's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Bankinter's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Bankinter's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Bankinter's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Bankinter's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Bankinter's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Bankinter's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Bankinter's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Bankinter's A.I Rankiteo Cyber Score in September 2025 ?
?
What is the average per-incident point impact on Bankinter's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Bankinter ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Bankinter's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?
Bankinter Cyber Scoring History | Rankiteo