Ransomware victim disclosure
← All victimsCitizens Pay (CTZPay)
Claimed by DYSPHOR1A · listed 2 hours ago
Status timeline
- ListedSep 6, 2026
Current state: Listed for ransom
At a glance
About the victim
AI dossier — public-source company profileCitizens Pay (CTZPay) is a mobile digital wallet and payment platform operating in Myanmar, powered by Myanmar Citizens Bank (MCB) and Capital Connect Limited. The platform offers instant money transfers, cash-in/cash-out services through authorized agents, bill payments, and loyalty rewards to Myanmar's unbanked consumers through a nationwide partner network.
- Industry
- Financial Services / Digital Payments
Attack summary
Severity: critical — Confirmed exfiltration of 209,970 user records containing PII, passwords, and device information from a financial payment platform; additionally compromised payment processing databases and infrastructure represent critical exposure of regulated financial services data at scale.DYSPHOR1A claims a full compromise of CTZPay's agent user information and related infrastructure, exfiltrating approximately 30 GB of data including user records, credentials, payment databases, and internal systems. The group is advertising the stolen data for sale at a price range of $7,000 to $25,000.
Data the group says was taken
AI dossier — extracted from the leak post- 209,970 agent user records
- Payment databases
- User credentials
- Device information
- Source code
- Infrastructure IPs
- Internal business data
What the group claims
Citizens Pay (also known as CTZPay) is a mobile digital wallet and payment platform in Myanmar powered by Myanmar Citizens Bank (MCB) and Capital Connect Limited.
The leak post
captured from the group's siteDigital Wallet / Payment Platform Digital Wallet / Payment Platform Citizens Pay (also known as CTZPay) is a mobile digital wallet and payment platform in Myanmar powered by Myanmar Citizens Bank (MCB) and Capital Connect Limited. Compromised agent user information — total data size 30 GB. Price range $7,000 to $25,000. Victim domain https://ctzpay.com. 209,970 user records — full dump Myanmar Broadband Telecom Co., Ltd. (MBT) is a leading fiber internet service provider and telecommunications network solutions company established in Myanmar in 2013. Full database compromise exposing 209,970 user records including PII, passwords, and device information. Source code, IPs, payment databases, customer PII — full infrastructure Netim is a French domain name registrar and web hosting provider. Full compromise of internal systems — source code, infrastructure IPs, payment processing databases, customer PII, and internal business data. 52,000 officer records + 4,000 facial photos Database containing records of 52,000 Indonesian police officers including email addresses, phone numbers, first and last names, passwords, location details, and 4,000 facial photographs. ### The University of De…
Data the group says was taken
- agent user information
Screenshot of the leak post

Sources
Source
Indexed 2 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

