Ransomware victim disclosure
← All victimsASHA Microfinance Bank Limited
listed as nigeria.asa-international.com · Claimed by Krybit · listed 5 hours ago
Status timeline
- ListedAug 2, 2026
- Data leakeddate unknown
At a glance
- Group
- Krybit
- Status
- Data leaked
- Country
- Nigeria
- Sector
- Professional Services
- Listed on leak site
- Aug 2, 2026
About the victim
AI dossier — public-source company profileASHA Microfinance Bank Limited (ASA Nigeria) is a regulated Nigerian microfinance institution licensed by the Central Bank of Nigeria. It serves approximately 172,000 clients across 269 branches, providing small loans primarily to low-income female business owners with an outstanding loan portfolio of USD 21.9 million.
- Industry
- Microfinance Banking
- Address
- 69 Allen Avenue, Ikeja, Lagos, Nigeria
Attack summary
Severity: high — Confirmed data exfiltration from a regulated financial institution serving 172k clients. Exposure of microfinance customer records (PII, financial data, loan details) and institutional financial information poses significant harm to individual borrowers and operational risk to the bank.The krybit ransomware group claims to have compromised ASHA Microfinance Bank Limited and published data from the breach. The group has disclosed the attack and published data, indicating exfiltration occurred.
Data the group says was taken
AI dossier — extracted from the leak post- client records
- loan portfolio data
- financial records
- customer personal information
What the group claims
ASHA Microfinance Bank Limited (ASA Nigeria) is a Nigerian for-profit deposit-taking microfinance institution, a fully l...
Sources
Source
Indexed 5 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

