Siinqee Bank Data Breach

Alleged

Ransomware claim involving Siinqee Bank

Published: Sep 21, 2026 LockBit
Threat Level
High
Confidence: High

Quick Summary

Alleged
Company
Siinqee Bank
Industry
Finance
Threat Actor
LockBit
Date of Incident
Sep 21, 2026

Executive Summary

LockBit 5 has claimed Siinqee Bank, a financial institution based in Somalia, as a victim, listing it on their dark web portal on September 21, 2026. This incident was identified through SOCRadar’s Dark Web Monitoring. The LockBit 5 group has been highly active, claiming 44 victims within the preceding 60 days. Their typical targets are concentrated in Professional Services, Manufacturing, and Healthcare sectors, primarily in the United States, Germany, and the Netherlands. Siinqee Bank’s inclusion presents a geographical divergence, as the East African financial sector is an unusual choice for this ransomware group. The targeting of Siinqee Bank by LockBit 5 deviates from the group’s usual pattern, which commonly focuses on North American and European entities within specific industries. While the ransomware group has claimed a significant number of victims in a short period, the selection of a Somali financial institution suggests a potential exploration of new or less conventional targets, or perhaps an opportunistic attack based on identified vulnerabilities. This particular victim’s profile does not align with the dominant industries and countries typically observed in LockBit 5’s operations.

Technical Analysis

SOCRadar’s Stealer-Log Signal monitoring identified the domain siinqeebank[.]com, revealing 25 records between September 12 and September 21, 2026. Among these findings were an employee credential on accounts.google[.]com associated with a corporate siinqeebank[.]com username, indicating potential access to Google Workspace. Additional findings include credentials for internal[.]siinqeebank[.]com and devwebsrv[.]siinqeebank[.]com, suggesting access to internal infrastructure and development environments. The recruitment portal subdomain was associated with 18 out of the 25 records, highlighting its significance. Furthermore, 23 external consumer email accounts were found on target-owned subdomains, and long-tail entries dating back to March 2025 were also present in stealer feeds. The critical finding from the stealer-log data is the compromised Google Workspace credential. Access to Google’s identity infrastructure can grant broad access across all connected workspace applications, potentially compromising a wide range of sensitive corporate data and operations. The presence of credentials for internal subdomains and development servers indicates a deeper level of network compromise or at least an attacker’s ability to enumerate and potentially access critical internal resources. The tight clustering of these harvested credentials just before the leak-site listing date (September 12–21, 2026) provides a strong correlation between the observed data exposure and the subsequent ransomware claim. The identified corporate Google account credential poses a significant risk due to the widespread use of Google Workspace for email, collaboration, and storage. Compromise of this account could provide attackers with access to internal communications, financial documents, customer data, and other sensitive information. The presence of credentials for development and internal infrastructure subdomains, along with a substantial number of records from the recruitment portal, suggests that attackers may have had a multi-faceted approach to gaining access or maintaining persistence within Siinqee Bank’s network. Continuous monitoring of dark web stealer feeds and diligent credential hygiene are essential steps to mitigate further impact.

Disclaimer

This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.

Is your data on the Dark Web?
Check dark web exposure for free.