ransomware Credible Gambia (GM) banking

Central Bank of The Gambia: Ransomware Data Auction

Central Bank of The Gambia

📅 08 November 2022
CompanyCentral Bank of The Gambia
Domaincbg.gm
CountryGambia (GM)
Sectorbanking
Breach date2022-11-08
People affectedNot disclosed
Ransomware groupALPHV
Data typesFinancial records, Personal data

Overview

In November 2022, the ALPHV ransomware group claimed to have breached the Central Bank of The Gambia (CBG) and stolen 2 TB of critical data. The group published a listing on its leak site stating that the data was for sale, with an auction open to buyers interested in acquiring financial and personal records belonging to the institution.

What was published

The listing stated that part of the stolen data could be downloaded, while the remainder was being negotiated for sale. According to the post, the auction was scheduled to close on December 7, with interested buyers directed to contact the group through a ProtonMail address. The claimed contents include financial data and personal information handled by the central bank.

Risks for affected individuals

  • Individuals whose data is held by the bank may face exposure of personal identifiers in the leaked records.
  • Financial information tied to the breach could be used for fraud or targeted social engineering.
  • The public nature of the auction increases the chance that the data circulates beyond the original buyers.

What remains unknown

  • The exact number of records or individuals affected was not disclosed in the listing.
  • It is not confirmed whether the full 2 TB was actually exfiltrated or whether the claims match the released sample.
  • The final outcome of the auction and the identity of any buyers remain unknown.

What affected people should do

Customers and partners of the Central Bank of The Gambia should monitor official communications from the bank for breach notifications. Anyone who suspects their financial information was exposed should contact their bank, review statements for unusual activity, and change credentials used on banking platforms. Institutions that transact with CBG should treat related emails with caution, as the stolen data could enable targeted phishing.