ransomware
Credible
Mauritania (MR)
finance
Bankily (Banque Populaire de Mauritanie) listed by the APT73 ransomware group
Bankily (Banque Populaire de Mauritanie)
CompanyBankily (Banque Populaire de Mauritanie)
Domainbankily.mr
CountryMauritania (MR)
Sectorfinance
Breach date2024-12-09
People affected200,000
Ransomware groupapt73
Data typesemployee data, customer data, mobile banking records
Overview
The APT73 ransomware group has listed Bankily, the mobile banking product of Banque Populaire de Mauritanie, on its leak site. The group's post references employee names and data including an administrator username. The listing appeared on 9 December 2024.
What was published
The group claims to have exfiltrated data related to the mobile banking product, including employee data and administrative information. The archive may also include customer data from the banking platform.
Risks for affected individuals
- Banking customers may be exposed to phishing.
- Employee data could enable targeted attacks.
- Administrative credentials, if exposed, are of concern.
What remains unknown
- The volume of data exfiltrated.
- Whether customer records are included.
- The response status of the bank.
What affected people should do
Customers should monitor account activity and be cautious of unsolicited messages. The bank should review affected systems, notify regulators and customers if data is involved, and communicate transparently.

Sources
- http://basherq53eniermxovo3bkduw5qqq5bkqcml3qictfmamgvmzovykyqd.onion/page_company.php?id=100