LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Bank of Africa Listed by medusa Ransomware Group

HIGH severityUnverified claimHow we verify

Bank of Africa Listed by medusa Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·January 30, 2023
Bank of Africa Listed by medusa Ransomware Group

Reported January 30, 2023.

HIGH
Severity
January 30, 2023
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The Bank of Africa Listed by medusa Ransomware Group (reported January 30, 2023) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

On 30 January 2023, Bank of Africa was listed on the leak site of the Medusa ransomware group. Public reporting states that internal files were exfiltrated in a ransomware attack. The number of people affected remains unknown, and further technical detail about timing, method, or confirmed contents has not been disclosed in the available record.

A listing of this kind matters because banks hold sensitive operational and customer-related information. Until independent confirmation or official statements clarify the scope, the claim itself is the primary public signal that data may have left the organisation’s control.

Inside the incident

According to the reported facts, Bank of Africa appeared on Medusa’s leak site on or around 30 January 2023. The sole concrete description of the compromise is that internal files were allegedly exfiltrated in a ransomware attack. No public figure has been given for the volume of data, the number of systems involved, or the precise date the intrusion began. The count of individuals whose information may have been touched is listed as unknown. Method of initial access, dwell time, and whether encryption was also deployed alongside exfiltration are undisclosed in the material available.

Because the listing originates from the threat actor’s own site, it constitutes a claim by Medusa rather than an independently verified confirmation of every asserted detail. No additional victim statement or regulatory filing expanding on these points is contained in the given record.

Who is medusa?

Medusa is a ransomware operation that has been publicly documented since at least 2021. Like many contemporary groups, it typically follows a double-extortion model: operators gain access to a network, move laterally, exfiltrate data, and then deploy ransomware while threatening to publish the stolen material if payment is not made. The group maintains a leak site on which it names victims and, in some cases, posts samples or full archives once deadlines pass.

Medusa has been observed targeting organisations across multiple sectors and geographies. Public reporting describes the use of common initial-access vectors such as compromised credentials or vulnerable internet-facing services, followed by data theft and extortion. Specific claims Medusa has made about Bank of Africa beyond the listing itself and the assertion of internal-file exfiltration are not detailed in the facts provided; any further assertions on the leak site should be treated as unverified claims by the group.

Bank of Africa and its sector

Bank of Africa is a banking group whose story began in Mali in 1982 with the creation of the first Bank of Africa, established with almost no external help. The group is headquartered in Dakar, Senegal. Since 2010 it has been majority-owned by BMCE Bank. As a commercial banking organisation operating across parts of Africa, it sits within a sector that routinely processes customer identity data, account and transaction records, credit information, and internal corporate documents.

Financial institutions are high-value targets because the data they hold can be used for fraud, identity misuse, or competitive intelligence. A ransomware incident affecting such an organisation therefore carries potential consequences both for the bank’s operations and for the individuals and businesses that rely on its services. The facts do not establish negligence or specific security failures; they simply record that the group was listed by Medusa in connection with claimed exfiltration of internal files.

What data was at risk

The available record names the exposed material only as “internal files exfiltrated in a ransomware attack.” No inventory of file types, customer databases, or specific data elements has been published in the facts. Organisations of this kind typically hold customer personal and financial information, employee records, internal correspondence, contracts, and operational documents. Whether any or all of those categories were present in the material Medusa claims to have taken remains unconfirmed.

Because the precise contents are undisclosed, it is not possible to state as fact which individuals or which categories of sensitive data were involved. The only confirmed public description is the threat actor’s claim of internal-file exfiltration.

The real-world impact

For people whose information may have been among the internal files, the practical risks include potential misuse of personal or financial details for fraud, phishing, or identity-related crime. Even when customer databases are not explicitly named, internal banking documents can contain enough identifiers to enable targeted social-engineering attempts. The number of people affected is unknown, so the scale of any such exposure cannot be quantified from public information.

For the organisation, a ransomware incident and public listing can disrupt operations, trigger regulatory and contractual notification duties, and damage trust. Recovery costs, forensic investigation, and any subsequent legal or supervisory scrutiny add further pressure. None of these outcomes is asserted here as having already materialised beyond the listing itself; they are the ordinary consequences that follow when a bank is named in this manner.

What to do if you're exposed

If you hold accounts or have other relationships with Bank of Africa, or if you simply want to check whether your details have appeared in known breach data, the following steps are prudent:

Public detail on this incident remains limited. Official updates from the bank or relevant authorities, if issued, should be treated as the authoritative source for any further action.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyBank of Africa security record
88/100
DoxxScan™ · Low doxx risk
B 83Good record

1 reported incident on record.

See Bank of Africa’s full breach history →

More recent breaches

Toyota Financial Listed by medusa Ransomware GroupNovember 16, 2023Moneris Solutions Listed by medusa Ransomware GroupNovember 13, 2023Mutuelle LMP Listed by medusa Ransomware GroupJuly 3, 2023Comisión Nacional de Valores Listed by medusa Ransomware GroupJune 11, 2023

Latest breaches

Read GalaxyWarden’s full analysis of the Bank of Africa Listed by medusa Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by medusa — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram