Reading Time: 2 minutes

Client Data Hacked Then Released

A major data breach at Standard Bank has taken a worrying turn after hackers publicly released stolen information.

The bank first disclosed the incident in March and has since issued updates to clients in April.

Now, with data reportedly circulating online, concerns about customer privacy and digital security have intensified. The breach involved unauthorised access to certain internal systems, not core banking platforms, but it still exposed sensitive client details. Here’s what happened and why it matters.

According to Standard Bank, the compromised data includes account numbers, limited account information, business names, and ID or registration numbers. The breach also affected Liberty Holdings, which confirmed that it detected and contained unauthorised access to some of its systems. The bank has stressed that its transactional systems remain secure and fully operational, and that it acted quickly with external experts to contain the incident.

However, a threat actor known as “Rootboy” claims to have accessed multiple internal platforms and extracted a large volume of data. While these claims have not been fully verified, the situation has raised serious questions about how such access was gained and how long it went undetected.

The real danger now may lie in what happens next. Cybersecurity experts warn that breaches like this often lead to a rise in scams, especially phishing attempts that use stolen personal details to appear convincing.

In South Africa, this often takes the form of SMS scams, fake calls, or messaging app fraud rather than email. Customers are being urged to stay alert, avoid sharing personal information, and report suspicious activity immediately.

Standard Bank says it has increased monitoring and fraud detection measures while continuing its investigation and working with regulators.