LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › CR2 Listed by avoslocker Ransomware Group

HIGH severityUnverified claimHow we verify

CR2 Listed by avoslocker Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·December 26, 2022
CR2 Listed by avoslocker Ransomware Group

Reported December 26, 2022.

HIGH
Severity
December 26, 2022
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The CR2 Listed by avoslocker Ransomware Group (reported December 26, 2022) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

On 26 December 2022, the ransomware group avoslocker listed CR2, an Irish-owned banking software company, on its leak site and claimed to have taken internal files in a ransomware attack. For customers of the banks that rely on CR2’s systems, and for anyone whose details may sit inside those systems, the practical question is straightforward: what was taken, who might be affected, and what can be done about it. Public detail remains limited; the number of people affected is unknown, and the precise contents of the haul have not been independently confirmed.

What is known is that CR2 supplies mobile, internet and ATM technology to more than 100 retail banks across Africa, the Middle East and Asia. A breach at a firm in that position can touch far more than the company’s own staff. This article sets out the reported facts, the background on the actor and the organisation, and the concrete steps people can take while fuller information is still missing.

Breaking down the breach

According to reporting dated 26 December 2022, CR2 was listed by the avoslocker ransomware group. The group claimed that internal files had been exfiltrated in a ransomware attack and that the volume of data exceeded 500 GB. Among the material the group said it held were sources to products CR2 had developed. No independent confirmation of the intrusion method, the exact date of access, or a full inventory of files has been published in the available record. The number of individuals whose personal data may have been involved is listed as unknown.

Ransomware incidents of this type typically involve both encryption of systems and theft of data before a ransom demand. In this case the public record centres on the leak-site listing and the claim of exfiltrated internal files; further technical detail about how the attackers gained entry, how long they remained inside the network, or whether systems were restored from backups is undisclosed.

Who is avoslocker?

Avoslocker is a ransomware operation that has been active in the public threat landscape for some years. Like many groups in this category, it has operated a double-extortion model: encrypting victim systems while also copying data and threatening to publish it on a dedicated leak site if payment is not made. The group has been observed offering its ransomware as a service to affiliates, who carry out intrusions and share proceeds with the core operators. Targets have spanned multiple sectors and regions rather than a single industry niche.

Listings on an avoslocker leak site are claims by the group. They indicate that the operators assert they hold data from a named organisation; they do not, by themselves, constitute independent verification of every file or every allegation. In the CR2 matter, the available facts record the listing and the group’s description of internal files and product source material; they do not supply a third-party audit of what was actually taken or released.

About CR2

CR2 is an Irish-owned company that builds and supplies banking software—mobile banking, internet banking and ATM platforms—to retail banks. It is headquartered in Dublin and maintains offices in Dubai, London, Cairo, Amman, Bengaluru, Lagos, Johannesburg, Singapore and Perth. Its customer base has included institutions such as ANZ, Barclays, Standard Chartered, Botswana Savings Bank, Jordan’s Bank al Etihad, the pan-African bank Orabank, and Nigeria’s Access Bank and Diamond Bank, among more than 100 retail banks across Africa, the Middle East and Asia.

Firms in this sector sit between banks and their customers. They hold source code, configuration data, operational documentation and, in many cases, access to or copies of data that banks use to run channels serving millions of account holders. A compromise at that layer can therefore affect not only the software vendor but also the confidentiality and integrity of services those banks provide. That is why a listing of CR2 by a ransomware group draws attention beyond the company’s own walls.

What was likely exposed

The facts state that internal files were exfiltrated in a ransomware attack and that the group claimed a volume of more than 500 GB, including sources to products CR2 had developed. Beyond that description, the exact data types and any personal records involved are not fully itemised in the public report. Organisations that build core banking channels typically hold source code, build systems, internal documentation, employee information, customer and partner contracts, and sometimes test or production-related data that may include identifiers or credentials used in banking environments. Whether any of those categories were present in the claimed haul, and in what form, remains unconfirmed.

Because the number of people affected is unknown and a detailed inventory has not been published, it is not possible to state as fact that specific categories of personal data—names, account numbers, identity documents or similar—were or were not included. Readers should treat the group’s leak-site claims as assertions pending further verification by the company or independent investigators.

Why it matters

For individuals, the risk depends on what actually left CR2’s environment. If employee or contractor records were among the internal files, those people may face phishing, identity misuse or credential stuffing that uses details only an insider source would hold. If any bank-related configuration, test data or customer-linked material was included, account holders at CR2’s client banks could see more convincing fraud attempts or pressure on the security of the channels they use. None of that is established as fact from the current record; it is the ordinary consequence of uncertainty when a vendor to many banks is listed by a ransomware group.

For CR2 and its banking customers, the incident raises operational and trust questions: integrity of product source code, possible exposure of internal processes, and the need to assess whether any downstream systems or credentials require rotation or monitoring. Ransomware groups use the threat of publication to increase pressure; even when full dumps are not released, the claim alone can force costly review and remediation. The absence of a confirmed headcount of affected individuals does not remove the need for vigilance among staff, partners and bank customers who rely on CR2 technology.

If your data was in this claimed breach

If you work for CR2, a partner, or a bank that uses its platforms, treat unsolicited messages that reference internal projects, colleagues or account details with caution. Prefer official channels when checking whether your employer or bank has issued guidance. Change passwords that may have been reused across work and personal accounts, enable multi-factor authentication where it is available, and monitor bank and credit activity for unfamiliar transactions. Keep records of any suspicious contact in case you need to report it later.

Public confirmation of exactly whose personal data was involved has not been provided, so many people will not know whether they are affected. You can run a free exposure scan of your email address to check whether your information has already surfaced in known breach data sets, and then decide on further steps such as credit monitoring or tighter account controls based on what you find.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyCR2 security record
88/100
DoxxScan™ · Low doxx risk
B 83Good record

1 reported incident on record.

See CR2’s full breach history →

More recent breaches

Public Employees Credit Union Listed by avoslocker Ransomware GroupDecember 26, 2022CPA Mutual Insurance Company Listed by avoslocker Ransomware GroupDecember 26, 2022Los Alamos Nature Center Listed by avoslocker Ransomware GroupDecember 26, 2022Xybion Listed by avoslocker Ransomware GroupDecember 26, 2022

Latest breaches

Read GalaxyWarden’s full analysis of the CR2 Listed by avoslocker Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by avoslocker — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram