Standard Bank data dumped daily after cyberattack ransom refusal

A hacker known as Rootboy has begun daily data dumps from Standard Bank's systems on the dark web since 14 April, following the bank's refusal to pay a 1 Bitcoin ransom. The attack, which started on 27 February, exfiltrated 1.2TB of data from Standard Bank and Liberty. The bank has confirmed exposure of some credit card details but no CVV numbers.

A cyberattack targeting Standard Bank and its subsidiary Liberty began on 27 February 2026, resulting in the exfiltration of 1.2TB of data from internal servers. According to the Prinz Eugen ransomware leak portal, the hackers sought a peaceful resolution but claimed Standard Bank abandoned its customers after two weeks of negotiations.

Rootboy, the threat actor, refused to wait for the 1BTC ransom payment and started releasing stolen data daily on the dark web from 14 April. The dumps have escalated: 5,000 lines of customer data initially, followed by 25,000, 50,000 yesterday—including staff data from SAP—and 100,000 today. The total package contains 154 million rows, including ID numbers, home addresses, and employment details.

Standard Bank confirmed that in limited cases, stolen information includes credit card numbers and expiry dates, but CVV numbers are unaffected. "We are communicating directly with those clients and proactively replacing their cards as a precaution," the bank stated. It added that it has reported the incident to regulatory and law enforcement authorities and is enhancing security measures.

Liberty issued a holding statement signed by CEO Yuresh Maharaj, similar to Standard Bank's, though its website lacks specific details on the breach amid other health-related articles.

相关文章

Dramatic illustration of a darknet leak of Swedish government IT data by hackers, showing computer screens with source code, passwords, and personal files.
AI 生成的图像

Swedish government IT data leaked on darknet

由 AI 报道 AI 生成的图像

A hacker group called ByteToBreach has leaked sensitive information from a government IT system on the darknet. The leak includes source code, passwords, and personal data from a platform managed by IT consultant CGI Sweden. Authorities like Cert-SE confirm they are aware of the reports but decline to comment.

A massive data breach has come to light, involving 149 million credentials left exposed online. The 98GB cache includes unique usernames and passwords from financial services, social media, and dating apps. The discovery highlights ongoing vulnerabilities in digital security.

由 AI 报道

Hackers have targeted Waltio, a French cryptocurrency accounting platform, demanding a ransom after stealing emails and tax reports from 50,000 customers. The company reported the incident on January 21, 2026, stating that no passwords or highly sensitive data were compromised. French authorities are now investigating the sophisticated cyberattack.

政府与私营部门联合调查小组确认,Coupang重大数据泄露事件中泄露了3367万条用户记录。这远超公司最初声称的3000个受影响账户,并宣布因延迟报告和证据不当处理而处以罚款并展开进一步调查。

由 AI 报道

Inditex, the textile group behind Zara, disclosed on Wednesday night an unauthorized access to internal databases hosted on a third-party provider's servers. The company states no customer personal data, such as names, phones or credit cards, was compromised. Operations remain fully unaffected.

A new report warns that adversaries are harvesting encrypted data today for future decryption using quantum computers, posing trillions in economic risks to banks. The Citi Institute estimates a single such attack could jeopardize $2 trillion to $3.3 trillion of U.S. GDP. Financial institutions must accelerate post-quantum preparations amid rising cyberattacks.

由 AI 报道

香港昂坪360缆车运营商周四在其内部网络中发现异常,并报警及通知个人资料私隐专员公署。调查确认部分数据被窃取,公司面临赎金要求。该公司已就事件向宾客、员工及持份者致歉。

 

 

 

此网站使用 cookie

我们使用 cookie 进行分析以改进我们的网站。阅读我们的 隐私政策 以获取更多信息。
拒绝