2026 Standard Bank South Africa — unauthorized access to client PII (Mar–Apr)
Data compromised
Names, ID numbers, company reg. numbers, contacts, account numbers per bank updates
Technical writeup
Standard Bank South Africa published March–April 2026 updates on unauthorized access to some personal information holdings, emphasizing that core banking systems remained operational and secure. As of mid-April disclosures on the group’s newsroom, potentially affected fields included names, South African ID numbers, company registration numbers, contact details, and account numbers, with the bank noting ongoing investigation with external experts and regulatory notification. Secondary reporting described large-volume exfiltration claims by an actor persona and separate discussion of payment-card subsets for a limited client set—treat headline terabyte figures as forum-sourced unless confirmed in bank statements.
Root cause
Unauthorized access to data stores holding client information (public attribution varied in press)