Bank of Africa Listed by medusa Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The Bank of Africa Listed by medusa Ransomware Group (reported January 30, 2023) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
On 30 January 2023, Bank of Africa was listed on the leak site of the Medusa ransomware group. Public reporting states that internal files were exfiltrated in a ransomware attack. The number of people affected remains unknown, and further technical detail about timing, method, or confirmed contents has not been disclosed in the available record.
A listing of this kind matters because banks hold sensitive operational and customer-related information. Until independent confirmation or official statements clarify the scope, the claim itself is the primary public signal that data may have left the organisation’s control.
Inside the incident
According to the reported facts, Bank of Africa appeared on Medusa’s leak site on or around 30 January 2023. The sole concrete description of the compromise is that internal files were allegedly exfiltrated in a ransomware attack. No public figure has been given for the volume of data, the number of systems involved, or the precise date the intrusion began. The count of individuals whose information may have been touched is listed as unknown. Method of initial access, dwell time, and whether encryption was also deployed alongside exfiltration are undisclosed in the material available.
Because the listing originates from the threat actor’s own site, it constitutes a claim by Medusa rather than an independently verified confirmation of every asserted detail. No additional victim statement or regulatory filing expanding on these points is contained in the given record.
Who is medusa?
Medusa is a ransomware operation that has been publicly documented since at least 2021. Like many contemporary groups, it typically follows a double-extortion model: operators gain access to a network, move laterally, exfiltrate data, and then deploy ransomware while threatening to publish the stolen material if payment is not made. The group maintains a leak site on which it names victims and, in some cases, posts samples or full archives once deadlines pass.
Medusa has been observed targeting organisations across multiple sectors and geographies. Public reporting describes the use of common initial-access vectors such as compromised credentials or vulnerable internet-facing services, followed by data theft and extortion. Specific claims Medusa has made about Bank of Africa beyond the listing itself and the assertion of internal-file exfiltration are not detailed in the facts provided; any further assertions on the leak site should be treated as unverified claims by the group.
Bank of Africa and its sector
Bank of Africa is a banking group whose story began in Mali in 1982 with the creation of the first Bank of Africa, established with almost no external help. The group is headquartered in Dakar, Senegal. Since 2010 it has been majority-owned by BMCE Bank. As a commercial banking organisation operating across parts of Africa, it sits within a sector that routinely processes customer identity data, account and transaction records, credit information, and internal corporate documents.
Financial institutions are high-value targets because the data they hold can be used for fraud, identity misuse, or competitive intelligence. A ransomware incident affecting such an organisation therefore carries potential consequences both for the bank’s operations and for the individuals and businesses that rely on its services. The facts do not establish negligence or specific security failures; they simply record that the group was listed by Medusa in connection with claimed exfiltration of internal files.
What data was at risk
The available record names the exposed material only as “internal files exfiltrated in a ransomware attack.” No inventory of file types, customer databases, or specific data elements has been published in the facts. Organisations of this kind typically hold customer personal and financial information, employee records, internal correspondence, contracts, and operational documents. Whether any or all of those categories were present in the material Medusa claims to have taken remains unconfirmed.
Because the precise contents are undisclosed, it is not possible to state as fact which individuals or which categories of sensitive data were involved. The only confirmed public description is the threat actor’s claim of internal-file exfiltration.
The real-world impact
For people whose information may have been among the internal files, the practical risks include potential misuse of personal or financial details for fraud, phishing, or identity-related crime. Even when customer databases are not explicitly named, internal banking documents can contain enough identifiers to enable targeted social-engineering attempts. The number of people affected is unknown, so the scale of any such exposure cannot be quantified from public information.
For the organisation, a ransomware incident and public listing can disrupt operations, trigger regulatory and contractual notification duties, and damage trust. Recovery costs, forensic investigation, and any subsequent legal or supervisory scrutiny add further pressure. None of these outcomes is asserted here as having already materialised beyond the listing itself; they are the ordinary consequences that follow when a bank is named in this manner.
What to do if you're exposed
If you hold accounts or have other relationships with Bank of Africa, or if you simply want to check whether your details have appeared in known breach data, the following steps are prudent:
- Monitor account statements and credit activity for unfamiliar transactions and report anything suspicious promptly to your bank and, where appropriate, to local fraud-reporting channels.
- Treat unsolicited messages that reference the bank or request credentials, codes, or payments with caution; verify through official channels before responding.
- Change passwords on related financial and email accounts, and enable multi-factor authentication where it is offered.
- Consider a credit freeze or fraud alert if you believe highly sensitive identifiers may have been involved and if such tools are available in your jurisdiction.
- Run a free exposure scan of your email address to see whether it has surfaced in previously recorded breach datasets.
Public detail on this incident remains limited. Official updates from the bank or relevant authorities, if issued, should be treated as the authoritative source for any further action.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Toyota Financial Listed by medusa Ransomware GroupMoneris Solutions Listed by medusa Ransomware GroupMutuelle LMP Listed by medusa Ransomware GroupComisión Nacional de Valores Listed by medusa Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the Bank of Africa Listed by medusa Ransomware Group →
Publicly posted by medusa — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.