Standard Bank Group listed by the PrinzEugen ransomware group
Standard Bank Group
Overview
The PrinzEugen ransomware group has claimed an attack on Standard Bank Group, one of Africa's largest banking groups, and states that around 1.2 TB of data was exfiltrated from internal servers. The group says the attack lasted three weeks, beginning on 27 February 2026, and also affected Liberty, the group's insurance arm.
What was published
The group's post describes a 1.2 TB exfiltration from internal servers affecting both Standard Bank and Liberty. At the time of analysis, the group's leak page was not reachable, so the full inventory of files could not be verified.
Risks for affected individuals
- A data set of this scale, if confirmed, would make customers a target for phishing and fraud.
- Banking records combined with personal data enable identity theft.
- The involvement of the insurance arm widens the potential impact.
What remains unknown
- Whether the 1.2 TB claim has been verified.
- The composition of the exfiltrated data.
- The response status of the bank and regulators.
What affected people should do
Customers should monitor accounts for unusual activity and never share one-time passwords. Standard Bank should issue an official statement, notify regulators, and provide clear guidance while the claim is investigated.
Sources
- http://prinzfkbjiazbrur4mjje6mntjc4vydx3iatkkzycufoylqcoo4y7pqd.onion/standard-bank-group