Ransomware victim disclosure
← All victimsStandard Bank
Claimed by PrinzEugen · listed 2 days ago
Status timeline
- ListedJun 15, 2026
- Data leakeddate unknown
At a glance
- Group
- PrinzEugen
- Status
- Data leaked
- Country
- South Africa
- Sector
- Finance/Banking
- Listed on leak site
- Jun 15, 2026
- Data size
- 1.2TB
- Records
- 154000000
About the victim
AI dossier — public-source company profileStandard Bank is a major financial institution operating in South Africa, providing banking and financial services to retail and corporate customers.
- Industry
- Finance/Banking
Attack summary
Severity: critical — Confirmed exfiltration of highly sensitive regulated financial and personal data at massive scale (1.2TB, 154M+ SQL rows) including PII, payment card data, government IDs, and financial records of potentially millions of customers in a highly regulated sector.PrinzEugen claims to have exfiltrated 1.2TB of data over a 3-week attack beginning February 27th, 2026. The group states negotiations with the bank failed and has published the stolen data, which includes customer PII, employee records, and transactional data.
Data the group says was taken
AI dossier — extracted from the leak post- Customer PII (names, addresses, emails, phone numbers)
- South African ID numbers
- Driver's license numbers
- Passport numbers
- Credit card numbers
- Bank account numbers
- Employee data
- Customer transactional records
- Corporate transactional records
What the group claims
3 week long attack beginning February 27th 2026 resulting in exfiltration of 1.2TB of data from internal servers. Peaceful resolution was sought but Standard Bank abandoned negotiations after 2 weeks.
The leak post
captured from the group's siteBeginning on February 27th 2026, The 3 week long attack on both Standard Bank and Liberty has resulted in 1.2TB of data being exfiltrated from internal servers. A peaceful resolution was sought out with Standard Bank, however after 2 weeks of back and forth they made the decision to abandon their customers. The haul of over 154,000,000 rows of exported SQL data includes but is not limited to: Customer PII (Full Names, Addresses, Emails, Phone Numbers, South African ID Numbers, Drivers License Numbers, Passport Numbers, Credit Card Numbers, Account Numbers), Detailed Employee Data, Bulk Customer and Corporate Transactional Data. This campaign has finalized. * ⚠ Could not reach file server.
Data the group says was taken
- Full Names
- Addresses
- Emails
- Phone Numbers
- South African ID Numbers
- Drivers License Numbers
- Passport Numbers
- Credit Card Numbers
- Account Numbers
- Employee Data
- Corporate Transactional Data
- Customer Transactional Data
- SQL Data
Screenshot of the leak post

Sources
Source
Indexed 2 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

