Merkanti Bank Ltd Listed by akira Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Merkanti Bank Ltd was listed by the Akira ransomware group on February 25, 2025, after internal files were exfiltrated in a ransomware attack. An undisclosed number of people may have been affected; check with the bank and monitor your accounts for any signs of compromise.
Merkanti Bank Ltd, a Malta-licensed credit institution formerly known as MFC Merchant Bank Ltd, has been listed by the ransomware group akira as a victim of a data-exfiltration attack. Public reporting of the listing dates to 25 February 2025. The number of people affected remains unknown, and the only data types publicly named are internal files said to have been taken during a ransomware incident. The group claims it is prepared to release essential corporate documents, including financial data such as audits, payment details and reports, together with internal databases. Beyond that claim, independent confirmation of the scale, method or precise contents of any breach has not been disclosed.
Because the organisation provides merchant banking, factoring and corporate banking services, any confirmed compromise of internal records could affect counterparties, clients and the bank’s own operations. At present the listing itself is an unverified claim by the threat actor; no further official verification has been made public.
What happened
According to the available record, Merkanti Bank Ltd appeared on the leak site associated with the akira ransomware group on or around 25 February 2025. The group asserts that it exfiltrated internal files in the course of a ransomware attack and states it is ready to upload a substantial volume of corporate material. No public details have been released about the initial intrusion vector, the duration of any access, whether encryption was deployed, or the exact volume of data involved. The number of individuals whose information may have been exposed is listed as unknown. All specifics beyond the group’s own claim remain undisclosed.
The group behind it: akira
Akira is a ransomware operation that has been active in public reporting since early 2023. Like many contemporary groups, it typically employs a double-extortion model: data are stolen before systems are encrypted, and the threat of publication is used to pressure victims into paying a ransom. The group has previously targeted organisations across multiple sectors, often advertising stolen material on dedicated leak sites. Its public statements are claims rather than independently Reported Facts; listings are therefore treated as assertions until corroborated by the victim or by forensic evidence released through official channels. In this instance, akira’s sole public statement concerning Merkanti Bank Ltd is the claim that essential corporate documents and internal databases have been taken and are ready for release. No additional statements specific to this victim have been recorded in the available facts.
Who is Merkanti Bank Ltd?
Merkanti Bank Ltd is a credit institution licensed by the Malta Financial Services Authority under registration number C31608. Previously operating as MFC Merchant Bank Ltd, it concentrates on merchant banking services, factoring and general corporate banking. Institutions of this type routinely handle sensitive commercial information—loan and factoring files, payment instructions, audited financial statements, client onboarding records and internal operational databases. Because the bank sits at the intersection of corporate finance and payment flows, a breach of its systems can have consequences that extend beyond the bank itself to the businesses and counterparties that rely on its services. The organisation’s regulated status also means any confirmed incident would attract scrutiny from Maltese and European financial supervisors.
What data was at risk
The only data types named in the public record are “internal files exfiltrated in a ransomware attack.” The group further claims these include financial data such as audits, payment details and reports, plus many internal databases. Exact contents, file counts and whether any personal data of natural persons were included have not been independently confirmed. Organisations engaged in merchant and corporate banking typically hold commercial contracts, transaction histories, know-your-customer documentation, employee records and system credentials. Until verified inventories are released, it is not possible to state with certainty which of these categories, if any, were actually taken. Readers should therefore treat the group’s description as an unverified claim rather than established fact.
Why it matters
For clients and counterparties, the principal risk is the potential exposure of commercial or financial information that could be misused for fraud, competitive disadvantage or further social-engineering attacks. Payment details and internal reports, if authentic and released, could enable targeted scams or identity-related fraud against businesses that bank with Merkanti. For the bank itself, a claimed incident would raise operational, regulatory and reputational issues, including possible notification duties under data-protection and financial-services rules. Because the number of affected individuals is unknown and the precise data set unconfirmed, the full scope of personal or commercial harm cannot yet be quantified. The incident nevertheless underscores the value that ransomware groups place on financial-sector data and the continuing need for robust detection and response capabilities in regulated institutions.
What to do if you're exposed
If you have a relationship with Merkanti Bank Ltd—whether as a corporate client, counterparty or employee—monitor account statements and payment instructions for unexpected activity and contact the bank through official channels to confirm whether your records are believed to be involved. Enable multi-factor authentication on any related online services and be alert to phishing attempts that reference the bank or the reported incident. Consider placing fraud alerts with relevant credit-monitoring services if personal identifiers may have been present. As a practical first step, readers can run a free exposure scan of their email address to check whether that address has already appeared in known breach data sets elsewhere. Official updates from the bank or from Maltese authorities should be treated as the authoritative source for any further guidance.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Trubee Wealth Advisors Listed by akira Ransomware GroupRosland Capital Listed by akira Ransomware GroupMD Manouel InsuranceAgency Listed by akira Ransomware GroupStanding Chapter 13 Trustee Listed by akira Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the Merkanti Bank Ltd Listed by akira Ransomware Group →
Publicly posted by akira — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.