{"id":642729,"date":"2026-04-22T12:06:30","date_gmt":"2026-04-22T10:06:30","guid":{"rendered":"https:\/\/mybroadband.co.za\/news\/?p=642729"},"modified":"2026-04-22T12:11:01","modified_gmt":"2026-04-22T10:11:01","slug":"standard-bank-sends-warning-to-customers-about-stolen-credit-card-details","status":"publish","type":"post","link":"https:\/\/mybroadband.co.za\/news\/security\/642729-standard-bank-sends-warning-to-customers-about-stolen-credit-card-details.html","title":{"rendered":"Standard Bank sends warning to customers about stolen credit card details"},"content":{"rendered":"\n<p>Standard Bank, South Africa&#8217;s largest bank by assets, sent notices to a new wave of customers, warning that their personal information had been accessed following a recent data breach.<\/p>\n\n\n\n<p>In emails sent to bank customers on Wednesday, Standard Bank said its ongoing investigation uncovered that more client credit card numbers had been shared online.<\/p>\n\n\n\n<p>Threat actor &#8220;ROOTBOY&#8221; claimed that he had breached the internal systems of Standard Bank and its subsidiary, Liberty, on 27 February 2026. The bank reported the breach publicly on 23 March.<\/p>\n\n\n\n<p>At the time, the bank said that <a href=\"https:\/\/mybroadband.co.za\/news\/security\/641250-1-2tb-of-standard-bank-data-including-credit-card-details-stolen-and-leaked-online.html\">its systems suffered &#8220;unauthorised access&#8221;<\/a> and that a limited number of customers were affected, with credit card details and other private information accessed.<\/p>\n\n\n\n<p>However, ROOTBOY later claimed to have exfiltrated 1.2TB of data from Standard Bank and Liberty&#8217;s systems after spending three weeks undetected inside their databases.<\/p>\n\n\n\n<p>In a post on a hacker forum, ROOTBOY threatened to release data belonging to Standard Bank customers in stages unless they received payment of R1.2 million in bitcoin.<\/p>\n\n\n\n<p>&#8220;A peaceful resolution was sought out with Standard Bank, however after 2 weeks of back and forth they made the decision to abandon their customers,&#8221; they said.<\/p>\n\n\n\n<p>ROOTBOY has been releasing new data from the stolen cache daily since 14 April, and Standard Bank has notified individual customers if their data was exposed.<\/p>\n\n\n\n<p>&#8220;We are writing to let you know about a recent incident identified by Standard Bank South Africa involving unauthorised access to some of your personal information,&#8221; the bank said in its email.<\/p>\n\n\n\n<p>&#8220;Our transactional systems were not accessed. They remain secure and operational and available to all our clients and employees.&#8221;<\/p>\n\n\n\n<p>Standard Bank disclosed that the information stolen by the threat actor included credit card numbers and expiry dates, but did not include CVV numbers \u2014 the 3-digit code on the back of cards.<\/p>\n\n\n\n<p>MyBroadband reviewed a portion of the information ROOTBOY stole from Standard Bank, and we can confirm that client names, ID numbers, phone numbers and physical addresses were included.<\/p>\n\n\n\n<p>The stolen data also included driver&#8217;s licence and passport numbers in certain cases. The threat actor also appeared to have stolen internal Standard Bank documents.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Standard Bank&#8217;s ongoing internal investigation<\/h2>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1200\" height=\"675\" src=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2026\/04\/Standard-bank-Email-1200x675.jpg\" alt=\"\" class=\"wp-image-642740\" srcset=\"https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2026\/04\/Standard-bank-Email-1200x675.jpg 1200w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2026\/04\/Standard-bank-Email-600x338.jpg 600w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2026\/04\/Standard-bank-Email-768x432.jpg 768w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2026\/04\/Standard-bank-Email-1536x864.jpg 1536w, https:\/\/mybroadband.co.za\/news\/wp-content\/uploads\/2026\/04\/Standard-bank-Email.jpg 1600w\" sizes=\"(max-width: 1200px) 100vw, 1200px\" \/><figcaption class=\"wp-element-caption\">Screenshot of the email Standard Bank sent to customers, warning that their credit card details were affected by the February breach.<\/figcaption><\/figure>\n\n\n\n<p>Standard Bank said in the email to customers that it launched a full investigation into the incident, which included reviewing whether any customer personal details were being actively exploited.<\/p>\n\n\n\n<p>&#8220;We have no indication of misuse of your data as a result of this incident,&#8221; it told the client in the email.<\/p>\n\n\n\n<p>ROOTBOY also threatened to leak sensitive data belonging to Standard Bank employees, which they had stolen from the system. The threat actor claimed a systemic attack on the bank&#8217;s ICT infrastructure.<\/p>\n\n\n\n<p>They allegedly breached and moved laterally through the bank&#8217;s Microsoft SharePoint, OneDrive, and Power Apps systems, as well as its Microsoft and Oracle SQL databases.<\/p>\n\n\n\n<p>Standard Bank said its operations were not affected by the breach and that only a limited set of credit card details were being leaked on the dark web.<\/p>\n\n\n\n<p>It added that external experts were joining its own teams in the ongoing investigation, and that it had reported the incident to the regulatory authorities, which included the Information Regulator.<\/p>\n\n\n\n<p>&#8220;We continue to strengthen controls and enhance monitoring in line with industry best practice to safeguard your information,&#8221; it stated.<\/p>\n\n\n\n<p>&#8220;We understand that this situation may be worrying and we sincerely apologise for any concern this may cause.&#8221;<\/p>\n\n\n\n<p>Standard Bank explained that criminals may use leaked information online to target customers through social engineering attacks. It warned clients not to share PINs, passwords, or OTPs with anyone.<\/p>\n\n\n\n<p>Customers should also update their banking app passwords and their social media platform passwords. Where possible, they should use biometric authentication to avoid account takeovers.<\/p>\n\n\n\n<p>&#8220;Contact us immediately if you notice any suspicious activity on your bank accounts or cards,&#8221; it told clients.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Standard Bank issued a new round of warnings to customers as a threat actor continued to leak people&#8217;s credit card numbers online following a data breach in February.<\/p>\n","protected":false},"author":341213,"featured_media":642073,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_sma_x_autopost_status":"idle","_sma_x_autopost_error":"","_sma_x_post_id":"","_sma_facebook_post_id":"","_sma_instagram_post_id":"","_sma_threads_post_id":"","_sma_x_attempts":0,"footnotes":""},"categories":[27],"tags":[104751,25945,123,9651,23371,104688,13889,1851,90450],"class_list":["post-642729","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","tag-banking-hack","tag-liberty","tag-microsoft","tag-microsoft-sharepoint","tag-onedrive","tag-rootboy","tag-sql","tag-standard-bank","tag-threat-actors"],"_links":{"self":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/642729"}],"collection":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/users\/341213"}],"replies":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/comments?post=642729"}],"version-history":[{"count":7,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/642729\/revisions"}],"predecessor-version":[{"id":642748,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/posts\/642729\/revisions\/642748"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media\/642073"}],"wp:attachment":[{"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/media?parent=642729"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/categories?post=642729"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mybroadband.co.za\/news\/wp-json\/wp\/v2\/tags?post=642729"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}