The Deutsche Bank breach is under investigation after the Unsafe ransomware group claimed to have stolen employee data and published alleged evidence on its leak site.

The attackers shared screenshots that appear to show database exports containing employee information. However, Deutsche Bank says the incident stems from a third-party service provider and that there is no evidence its internal systems were compromised.

Ransomware Group Publishes Alleged Database Records

Unsafe listed Deutsche Bank on its dark web leak site and released screenshots that appear to contain database extracts.

The images reportedly show terminal output and database queries that reference employee information. Researchers reviewing the samples identified records linked to Deutsche Bank staff.

The leaked data allegedly includes employee email addresses, password hashes, physical addresses, and internal database records.

Researchers say the available evidence does not confirm whether customer information was included in the alleged breach.

Deutsche Bank Points to Third-Party Provider

Deutsche Bank says attackers did not breach its internal infrastructure.

According to the bank, the incident affected an external service provider in Germany that operates a marketing and incentive platform for sales partners.

The bank says it has found no evidence that attackers accessed its internal systems or corporate network. It also continues to investigate the incident with the provider to reduce potential cyber risks.

Employee Data Could Support Future Attacks

Even if attackers only obtained employee information, the incident could still create serious security risks.

Cybercriminals could use the stolen email addresses to launch targeted phishing campaigns. Password hashes may also become valuable if attackers manage to crack them offline.

Internal records can also help threat actors understand an organization’s structure. That information may support future social engineering attacks or attempts to target privileged accounts.

Deutsche Bank Has Faced Previous Cyber Incidents

The alleged Deutsche Bank breach is not the first cybersecurity incident involving the financial institution.

In 2023, the MOVEit data breach affected Deutsche Bank after attackers exploited vulnerabilities in the widely used file transfer platform.

The same year, another threat actor claimed to possess sensitive Deutsche Bank files that were allegedly stolen during a LockBit ransomware attack.

Unsafe Ransomware Returns After Years of Silence

Unsafe operates as a ransomware-as-a-service group and uses double-extortion tactics. The gang encrypts victim systems while also threatening to publish stolen data.

Security researchers say the group has used zero-day vulnerabilities and malware families such as Emotet and GandCrab during previous campaigns.

Although Unsafe remained largely inactive throughout 2024 and 2025, it has re-emerged in 2026. Since then, the group has targeted organizations across Germany, the United States, Switzerland, and France.


0 responses to “Deutsche Bank Investigates Third-Party Breach After Ransomware Claim”