Anyway, I don't care about the hacktivism and propaganda (don't really get it -- tbh,rich people bad/corrupt?) But would very much be interested in any post-incident analysis of what happend.
But here's what stands out to me: they're talking about using empire and hvnc. Empire is by design detectable,you could use the techniques in empire in your own malware though. Most rats and bots (take trickbot) let you sniff key strokes, run commands,etc... So I guess they used psexec or winrm to access the hosts(no vlan segmentation or firewall on endpoints!?). I ask all this because the specific MO is significantly different than what is seen with criminal actors and crimeware(like Carbank which She mentions). And to me, it does corroborate the story that this was likely an independent hacker motivated by hacktivism as opposed to a bigger conspiracy to burn some group and plant false records in the leak (which could still less likely be the case)
Very exciting,righteous hack.
I think overall, the bank cheaped out on IT and paid big time for it.