American Bank Trusts Ransomware Gang's Pinky Promise to Delete Stolen Data
There is a word appearing in Flagstar Bank's recent breach disclosure that you almost never see in these things: 'removed.'
Not stolen. Not copied. Not exfiltrated. Removed.
The choice of language is doing a lot of heavy lifting here. When a ransomware crew breaks into your systems and walks out with customer data, 'removed' implies the data is simply gone — vanished from existence, like they did you a favour by tidying up. The bank appears to be taking the attackers at their word that the data was deleted after the ransom was, presumably, dealt with.
This is the kind of institutional optimism that should give anyone pause.
The standard vocabulary in breach notifications is 'stolen,' which is at least honest about the direction of travel, even if technically imprecise. Data isn't stolen in the traditional sense — it's copied. The original stays put. The victim just loses exclusive possession of it, which is arguably worse than a physical theft because you can't always tell what's gone.
Further down the spectrum of corporate euphemism you get 'acquired' and 'retrieved,' which sound almost academic. 'Affected' is popular with legal teams who've been told to say as little as possible. And then there's 'accessed' — the classic non-admission, a word that implies someone had a look around without necessarily implying anything was taken at all.
But 'removed' is something else entirely. It's an active claim about what happened after the breach — specifically, that the data no longer exists in the hands of criminals. Which would be a lovely outcome, if ransomware gangs were known for keeping their promises.
They aren't.