Central Bank of Libya listed by the Qilin ransomware group
Central Bank of Libya
Overview
The Qilin ransomware group has listed the Central Bank of Libya (CBL), the country's monetary authority, on its leak site. The listing appeared on 22 June 2026. A compromise of a central bank represents an incident with national financial implications.

What was published
The group has listed the bank as a victim but has not published detailed data descriptions at this stage. The potential contents of any exfiltration would depend on which internal systems were accessed, ranging from administrative records to payment and settlement infrastructure data.
Risks for affected individuals
- Banking infrastructure data could be used in further attacks against Libyan financial institutions.
- Internal records may expose operational and personnel information.
- Any exposure of payment system details carries systemic risk.
What remains unknown
- Whether data has been exfiltrated and in what volume.
- Which systems were accessed.
- The response status of the bank and Libyan authorities.
What affected people should do
The Central Bank of Libya should conduct a review of the affected systems, notify partner institutions, and coordinate with national cybersecurity authorities. Financial institutions in Libya should watch for suspicious activity related to their systems.
Sources
- http://ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion/site/blog?uuid=7c1bd27c-bdf7-46e1-9aa7-3652fa370f25