Skip to content
Deutsche Bank probes supplier cyber incident after ransomware gang claims breach

Deutsche Bank probes supplier cyber incident after ransomware gang claims breach

Computing July 9, 2026

Deutsche Bank is investigating a cybersecurity incident involving an external service provider after a ransomware group claimed to have breached the German lender and published what it said was evidence of stolen employee data.

The ransomware gang, known as Unsafe, listed Deutsche Bank on its dark web leak site, claiming it had gained access to the bank's internal systems.

To support its claim, the group released screenshots appearing to show database extracts, terminal commands and records containing employee information.

The published material appears to include employee email addresses, password hashes, physical addresses and internal database records.

Researchers at Cybernews said the samples suggest the data relates to Deutsche Bank employees but added that they could not determine whether any customer information had also been compromised.

A spokesperson for Deutsche Bank said the incident did not involve the bank's own network but instead affected a third-party company in Germany that runs a marketing and incentive platform for Deutsche Bank's sales partners.

"We have been informed of a cybersecurity incident at an external service provider," the spokesperson said, adding that there was "no indication that Deutsche Bank's internal systems or networks were or are affected" and no evidence of unauthorised access to the bank's network.

The bank said it was continuing to investigate the incident alongside the service provider and was working to minimise any potential cyber risks.

Although the available evidence points primarily to employee information, experts warned that such data could still present significant risks. Stolen employee records can be used to launch targeted phishing campaigns, attempt to crack passwords or support further attacks against an organisation.

Internal corporate information may also help cybercriminals understand a company's systems and identify employees with privileged access for more sophisticated social engineering attempts.

Unsafe operates under the increasingly common ransomware-as-a-service model, in which developers lease malware to affiliates who carry out attacks.

The group is also known for using "double extortion" tactics, encrypting victims' systems while threatening to publish stolen data unless a ransom is paid.

The gang has previously exploited software vulnerabilities to gain initial access before disabling security controls and maintaining persistence inside compromised networks.

After a relatively quiet period during 2024 and 2025, the group has re-emerged this year, with organisations in Germany, the United States, Switzerland and France among its reported targets.

The alleged breach illustrates how cyber incidents involving third-party providers can expose major organisations to security risks, particularly in the financial sector, where banks depend on a wide network of external technology providers.

Last year, US financial services company SitusAMC disclosed a data breach affecting information linked to its banking clients, prompting several major banks to assess their potential exposure and review security measures across their supplier networks.

Deutsche Bank has also been caught up in third-party cyber incidents in the past.

In 2023, it was among organisations affected by the mass exploitation of the MOVEit file-transfer software, while the same year a separate threat actor claimed to be selling files allegedly stolen from the bank.

Extracted Entities