Unverified claim — July 7, 2026: The Unsafe ransomware group listed Deutsche Bank on its dark-web leak site, posting screenshots that appear to show employee database exports—emails, password hashes, and physical addresses—according to Cybernews. Deutsche Bank had not publicly confirmed the incident at catalog time.
What Unsafe claimed
Cybernews reported the gang published terminal output and SQL-style extracts as "proof," suggesting access to internal HR or identity databases rather than retail customer cores. Researchers could not determine from samples alone whether customer banking data was included.
Unsafe's 2026 resurgence
Unsafe operates a ransomware-as-a-service model with double-extortion tactics. After going quiet in 2024–2025, the group re-emerged aggressively in 2026 with victims reported across the US, Germany, Switzerland, and France—making a Deutsche Bank listing a high-visibility escalation even if unconfirmed.
Employee-data leaks still matter
Even "only employees" exposures fuel:
- Targeted phishing using real @db.com addresses and office locations
- Offline hash cracking if password hashes are weak
- Lateral movement mapping for follow-on intrusion
Context: verified prior Deutsche Bank incidents
BreachHistory separately tracks Deutsche Bank's verified 2023 MOVEit provider breach (Majorel)—customer account-switching data via Cl0p—not this July 2026 Unsafe marketing post.
Action items
- Deutsche Bank staff: report suspicious MFA prompts; do not trust unsolicited "IT reset" calls.
- Customers: no attested customer impact yet—watch official db.com notices only.
- Security teams: hunt for Unsafe IOCs if your firm integrates with Deutsche Bank infrastructure.
Canonical record: Deutsche Bank Unsafe claim 2026 (unverified).