ransomware Credible Libya (LY) government

Central Bank of Libya listed by the Qilin ransomware group

Central Bank of Libya

📅 22 June 2026
CompanyCentral Bank of Libya
CountryLibya (LY)
Sectorgovernment
Breach date2026-06-22
People affected500,000
Ransomware groupqilin
Data typesfinancial systems data, banking records, internal documents

Overview

The Qilin ransomware group has listed the Central Bank of Libya (CBL), the country's monetary authority, on its leak site. The listing appeared on 22 June 2026. A compromise of a central bank represents an incident with national financial implications.

Central Bank of Libya leak listing

What was published

The group has listed the bank as a victim but has not published detailed data descriptions at this stage. The potential contents of any exfiltration would depend on which internal systems were accessed, ranging from administrative records to payment and settlement infrastructure data.

Risks for affected individuals

  • Banking infrastructure data could be used in further attacks against Libyan financial institutions.
  • Internal records may expose operational and personnel information.
  • Any exposure of payment system details carries systemic risk.

What remains unknown

  • Whether data has been exfiltrated and in what volume.
  • Which systems were accessed.
  • The response status of the bank and Libyan authorities.

What affected people should do

The Central Bank of Libya should conduct a review of the affected systems, notify partner institutions, and coordinate with national cybersecurity authorities. Financial institutions in Libya should watch for suspicious activity related to their systems.

Sources

  • http://ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion/site/blog?uuid=7c1bd27c-bdf7-46e1-9aa7-3652fa370f25