Security22.04.2026

Standard Bank sends warning to customers about stolen credit card details

Standard Bank, South Africa’s largest bank by assets, sent notices to a new wave of customers, warning that their personal information had been accessed following a recent data breach.

In emails sent to bank customers on Wednesday, Standard Bank said its ongoing investigation uncovered that more client credit card numbers had been shared online.

Threat actor “ROOTBOY” claimed that he had breached the internal systems of Standard Bank and its subsidiary, Liberty, on 27 February 2026. The bank reported the breach publicly on 23 March.

At the time, the bank said that its systems suffered “unauthorised access” and that a limited number of customers were affected, with credit card details and other private information accessed.

However, ROOTBOY later claimed to have exfiltrated 1.2TB of data from Standard Bank and Liberty’s systems after spending three weeks undetected inside their databases.

In a post on a hacker forum, ROOTBOY threatened to release data belonging to Standard Bank customers in stages unless they received payment of R1.2 million in bitcoin.

“A peaceful resolution was sought out with Standard Bank, however after 2 weeks of back and forth they made the decision to abandon their customers,” they said.

ROOTBOY has been releasing new data from the stolen cache daily since 14 April, and Standard Bank has notified individual customers if their data was exposed.

“We are writing to let you know about a recent incident identified by Standard Bank South Africa involving unauthorised access to some of your personal information,” the bank said in its email.

“Our transactional systems were not accessed. They remain secure and operational and available to all our clients and employees.”

Standard Bank disclosed that the information stolen by the threat actor included credit card numbers and expiry dates, but did not include CVV numbers — the 3-digit code on the back of cards.

MyBroadband reviewed a portion of the information ROOTBOY stole from Standard Bank, and we can confirm that client names, ID numbers, phone numbers and physical addresses were included.

The stolen data also included driver’s licence and passport numbers in certain cases. The threat actor also appeared to have stolen internal Standard Bank documents.

Standard Bank’s ongoing internal investigation

Screenshot of the email Standard Bank sent to customers, warning that their credit card details were affected by the February breach.

Standard Bank said in the email to customers that it launched a full investigation into the incident, which included reviewing whether any customer personal details were being actively exploited.

“We have no indication of misuse of your data as a result of this incident,” it told the client in the email.

ROOTBOY also threatened to leak sensitive data belonging to Standard Bank employees, which they had stolen from the system. The threat actor claimed a systemic attack on the bank’s ICT infrastructure.

They allegedly breached and moved laterally through the bank’s Microsoft SharePoint, OneDrive, and Power Apps systems, as well as its Microsoft and Oracle SQL databases.

Standard Bank said its operations were not affected by the breach and that only a limited set of credit card details were being leaked on the dark web.

It added that external experts were joining its own teams in the ongoing investigation, and that it had reported the incident to the regulatory authorities, which included the Information Regulator.

“We continue to strengthen controls and enhance monitoring in line with industry best practice to safeguard your information,” it stated.

“We understand that this situation may be worrying and we sincerely apologise for any concern this may cause.”

Standard Bank explained that criminals may use leaked information online to target customers through social engineering attacks. It warned clients not to share PINs, passwords, or OTPs with anyone.

Customers should also update their banking app passwords and their social media platform passwords. Where possible, they should use biometric authentication to avoid account takeovers.

“Contact us immediately if you notice any suspicious activity on your bank accounts or cards,” it told clients.

Show comments

Latest news

More news

Trending news

Poll

Which operating system do you have installed on your personal computer?

View Results

Loading ... Loading ...
Sign up to the MyBroadband newsletter