Ransomware victim disclosure
← All victimsBOK Financial
Claimed by Shinyhunters · listed 1 day ago
Status timeline
- ListedAug 22, 2026
- Data leakeddate unknown
At a glance
- Group
- Shinyhunters
- Status
- Data leaked
- Country
- United States
- Sector
- Financial Services
- Listed on leak site
- Aug 22, 2026
About the victim
AI dossier — public-source company profileBOK Financial (BOKF, NA) is a US-based FDIC-insured bank offering personal and commercial banking services including checking, savings, mortgages, auto loans, credit cards, and wealth advisory services. The organization operates multiple locations and supports significant community involvement.
- Industry
- Financial Services - Banking
Attack summary
Severity: high — BOK Financial is a regulated financial institution holding customer deposits, personal financial data, and account information at scale. Confirmed exfiltration of banking customer data represents significant regulatory and privacy breach risk, even without specifics on data scope in this truncated post.ShinyHunters claims to possess exfiltrated data from BOK Financial and issued a final extortion warning on 22 August 2026, threatening to leak the data if contact and payment were not made by end of day 24 August 2026. No specific data categories or proof files are detailed in the truncated leak post.
What the group claims
This is a final warning to reach out by end of day 24 Aug 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 22 Aug 2026 | Warning: FINAL WARNING PAY OR LEAK
Sources
- Victim sitebokfinancial.com
Source
Indexed 1 day agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

