Bank Rakyat Listed by hunters Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Bank Rakyat appeared on the hunters ransomware group’s leak site on 10 September 2024, with the group claiming to have stolen internal files. The number of individuals affected has not been disclosed, so customers should review any alerts from the bank and monitor their accounts for unusual activity.
When a financial institution appears on a ransomware group's listing, the immediate concern for customers and staff is whether personal or account-related information has left the organisation's control. In the case of Bank Rakyat, a Malaysian banking entity, the group known as hunters claimed on 10 September 2024 to have taken internal files. The number of people potentially affected remains unknown, and public detail on the precise contents is limited, yet any exposure of banking-related material carries practical risks of fraud, identity misuse and lasting disruption for those whose records may be involved.
This report sets out only what has been stated in available records of the incident. It does not assume confirmation of the claim, nor does it invent scale, methods or specific data elements beyond the limited facts provided.
What happened
On 10 September 2024, Bank Rakyat was listed by the hunters ransomware group. The available summary states that the organisation is based in Malaysia, that data was exfiltrated, and that data was not encrypted. The listing characterises the event as a ransomware attack in which internal files were taken. No further public detail has been given on the timing of any intrusion, the technical method used, the volume of material involved, or whether the organisation has verified the claim. The number of people affected is recorded as unknown. These points constitute the entirety of the disclosed incident facts; everything else remains unconfirmed.
Inside hunters
Hunters is a ransomware operation that has appeared in public reporting as a group that conducts double-extortion style campaigns: it claims to steal data and then threatens to publish it if demands are not met. Like other actors of this type, it maintains a leak site on which it posts victim names and, at times, samples or larger archives of allegedly stolen material. The group’s listings are claims made by the actors themselves; they are not independent confirmations that a breach occurred or that the described data was in fact obtained. In this instance, hunters has listed Bank Rakyat and asserted that internal files were exfiltrated without encryption of systems. No additional statements attributed specifically to this victim beyond that listing appear in the available record. Public knowledge of the group’s broader pattern—targeting organisations across sectors, advertising stolen data, and using leak sites for pressure—provides context but does not establish the accuracy of any single claim.
About Bank Rakyat
Bank Rakyat is a Malaysian financial institution that operates in the banking and cooperative finance sector. Organisations of this kind typically hold customer account details, identification records, transaction histories, employee information and internal operational documents. Because banks sit at the centre of personal and commercial financial life, any unauthorised access to their systems can affect large numbers of account holders, staff and counterparties. A listing of this nature is consequential precisely because of the sensitivity of the data such institutions routinely process and the trust placed in them by the public. The facts do not state that Bank Rakyat has confirmed a breach or described its own assessment of impact; the record is limited to the group’s claim and the basic attributes noted above.
The information in question
The facts name the exposed material only as “internal files exfiltrated in ransomware attack.” No more granular inventory—such as customer lists, account numbers, identity documents or specific file categories—has been disclosed. For a bank, internal files could in principle encompass a wide range of records, but that possibility is not evidence. Exact contents remain unconfirmed. Readers should treat any assertion of particular data types as speculative unless and until the organisation or independent investigators publish verified details.
The real-world impact
If internal files from a bank have been taken, the concrete risks for individuals include attempted account takeovers, phishing that uses accurate personal details, fraudulent loan or credit applications, and longer-term identity-related problems. Even when encryption of systems did not occur, the mere possession of internal material by outsiders can enable social-engineering attacks against customers and employees. For the organisation itself, the consequences can include regulatory scrutiny, remediation costs, reputational damage and the need to notify affected parties once the scope is understood. Because the number of people affected is unknown and the precise data set is undisclosed, the scale of these risks cannot yet be quantified. The absence of encryption, as claimed, may have limited operational disruption, but it does not eliminate the exposure of whatever files were allegedly removed.
If your data was in this claimed breach
Anyone who holds an account or other relationship with Bank Rakyat should monitor statements and official communications from the bank for any confirmation or guidance. Practical first steps include reviewing recent account activity for unfamiliar transactions, enabling multi-factor authentication where available, treating unsolicited messages that reference banking details with caution, and considering a credit or fraud alert with relevant Malaysian agencies if identity documents may have been involved. Because the full contents remain unconfirmed, these measures are precautionary rather than responses to proven exposure of any specific record. Readers can also run a free exposure scan of their email address to check whether that address has already appeared in other known breach data sets; such a check does not confirm or rule out involvement in this particular incident, but it can surface other exposures that warrant attention.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Development Bank of Jamaica Listed by hunters Ransomware GroupSouthern Acids Listed by hunters Ransomware GroupBanco Sucredito Regional S.A.U. Listed by hunters Ransomware GroupICBC (London) Listed by hunters Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the Bank Rakyat Listed by hunters Ransomware Group →
Publicly posted by hunters — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.