DBSA hit by ransomware attack. Listed by akira Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The DBSA hit by ransomware attack. Listed by akira Ransomware Group (reported June 22, 2023) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
In mid-2023, people connected to the Development Bank of Southern Africa learned that a ransomware group had listed the institution as a victim and claimed to have taken internal files. When a development finance organisation is named in this way, the practical concern is straightforward: staff, partners, clients and counterparties may find that operational or personal information has left the organisation’s control, even if the full picture remains incomplete. Public detail is limited, the number of people affected is unknown, and the exact contents of any taken material have not been independently confirmed.
What is known comes largely from a listing attributed to the Akira ransomware group and from the sparse reporting that followed. The incident matters because banks and development lenders hold sensitive commercial and personal records as a matter of course; any credible claim that internal files were removed raises lasting questions about exposure, recovery and trust.
What happened
According to reporting dated 22 June 2023, DBSA was listed by the Akira ransomware group in connection with a ransomware attack. The group’s own statement on the matter asserted that the bank had been attacked using Akira ransomware by an actor operating without permission or approval from the group’s side, that the group was ready to assist DBSA in recovering its systems, that an internal investigation was under way to ensure DBSA information was not leaked, and that a bank representative would be given full details of the incident. The listing further indicated that internal files had been exfiltrated.
No independent confirmation of the attack method, the precise timing of intrusion or encryption, the volume of data involved, or the outcome of any negotiations has been supplied in the available record. The number of people affected remains unknown. Public reporting does not establish whether systems were restored from backups, whether a ransom was paid, or whether the claimed files were ever released more widely. In short, the core facts rest on the group’s claim and on the fact of the listing itself; much else is undisclosed.
Who is akira?
Akira is a ransomware operation that became prominent in 2023. Like other groups in this category, it typically gains access to corporate networks, moves laterally, exfiltrates data, and then deploys encryption while threatening to publish the stolen material if payment is not made. The group has maintained a leak site on which it names victims and, in some cases, posts samples or larger archives of claimed data. Its victims have spanned multiple sectors and countries; the pattern is opportunistic rather than confined to a single industry.
In this instance the group’s listing of DBSA should be treated as an unverified claim. Nothing in the public facts states that every assertion on the leak site is accurate, nor do the facts record any specific additional statements Akira made about DBSA beyond the summary already noted. Attribution of the intrusion to Akira therefore rests on the group’s own branding of the attack and on the contemporaneous reporting that repeated that claim.
About DBSA
DBSA is the Development Bank of Southern Africa, a development finance institution that provides funding and related services for infrastructure and economic development projects across the region. Organisations of this type routinely handle commercial loan files, project documentation, counterparty records, internal financial and operational data, and personal information belonging to employees, applicants and partners. Because the work involves public-interest infrastructure and cross-border finance, the institution sits at the intersection of government, private sector and community stakeholders.
A ransomware incident affecting such a body is consequential not only for the bank’s own continuity but for the confidence of those who share sensitive information with it. Even when the precise scope of data loss is unconfirmed, the mere appearance of the organisation on a ransomware leak site can prompt counterparties, regulators and individuals to reassess how their information is protected.
The information in question
The available facts state only that internal files were exfiltrated in the ransomware attack. No further breakdown of file types, record counts or categories of personal or commercial data has been disclosed. It is therefore not possible to state as fact which specific fields or documents left the organisation’s control.
Development banks and similar lenders typically hold a mix of corporate records, project and credit files, contracts, internal correspondence, and personal data of staff and external parties. Whether any of those categories were among the material Akira claimed to possess remains unconfirmed. Readers should treat the phrase “internal files” as the limit of what has been publicly named and should not assume a wider or narrower inventory without additional evidence.
Why it matters
For individuals, the real-world risk is that personal or professional details—if they were present in the taken files—could be misused for fraud, social engineering or unwanted contact. Because the number of people affected is unknown and the exact data types are unconfirmed, it is impossible to quantify that risk precisely; the prudent stance is simply to recognise that exposure cannot yet be ruled out.
For the organisation, the incident raises operational, legal and reputational questions. Ransomware can disrupt core systems, force costly recovery work and trigger notification or regulatory obligations. A public listing by a ransomware group can also affect relationships with funders, project partners and the communities the bank serves. None of this establishes negligence as a proven fact; it simply describes the ordinary consequences that follow when a financial institution is named in this way and internal files are claimed to have been removed.
If your data was in this claimed breach
If you have a past or present connection to DBSA—as an employee, applicant, client, contractor or partner—consider basic protective steps. Monitor financial and email accounts for unexpected activity, treat unsolicited messages that reference the bank or your projects with caution, and enable stronger authentication where it is offered. If you receive notice directly from DBSA, follow the instructions it provides. Because public detail on this incident remains limited, official updates from the organisation itself are the most reliable source of further information.
You can also run a free exposure scan of your email address to check whether your information has already surfaced in known breach data sets. That step will not confirm or deny involvement in this specific incident, but it can help you see whether your address appears in other publicly indexed breaches and decide what additional monitoring is worthwhile.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Edge Solutions | Stone Ridge Payments Listed by akira Ransomware GroupMilliman Financial Risk Management LLC (Milliman, Inc. subsidiary) Listed by akira Ransomware GroupSouthwood Financial,SWF FUNDING LLC, EduCap Inc. Listed by akira Ransomware GroupCohn Lifland Pearlman Herrmann and Knopf Listed by akira Ransomware GroupLatest breaches
Publicly posted by akira — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.