Search TorWire

Find cybersecurity guides and research articles

Home > News > Cybersecurity > LockBit 5.0 Claims Attack on Ethiopian Bank Siinqee, with No Breach Evidence Found

LockBit 5.0 Claims Attack on Ethiopian Bank Siinqee, with No Breach Evidence Found

By: Jordan Vector — Cybersecurity Expert

Last updated: September 21, 2026

Human Written
LockBit 5.0 Claims Attack on Ethiopian Bank Siinqee, with No Breach Evidence Found
  • LockBit 5.0 allegedly added Siinqee Bank to its victim list on September 21, 2026. Public threat feeds now link siinqeebank.com to the group.

  • The claim remains unverified. No public proof reviewed so far shows stolen data, locked files, a ransom demand, or a known way in.

  • Siinqee Bank runs a broad digital banking service in Ethiopia. It offers mobile, online, card, agent and digital loan services.

LockBit 5.0 ransomware group just named Siinqee Bank as one of its new victims. The entry reported appeared on September 21 in threat feeds from several ransomware monitoring platforms.

One tracker lists the entry as ‘lockbit5’ and gives September 21 as the date. Another says LockBit 5.0 claims to have hit the group behind the site. Data from Ransomware.live also recorded LockBit 5.0 publishing siinqeebank.com as a new victim.

It’s, however, worth noting that these feeds report what a ransomware group says on its leak site. They’re not proof that the attack took place.

GalaxyWarden, a service that tracks ransomware claims, marks the Siinqee entry as unverified. It says the claim came from a LockBit leak-site post and has not had outside proof.

No Evidence of Breach or Data Theft

Many important things remain unclarified. No report gives an exact number of stolen data by the attackers. The available reports also do not mention any ransom demand or explain how the attackers may have gained access to the bank.

There is no mention of hit systems either. There is no independent confirmation that LockBit ransomware locked Siinqee’s systems or caused a service outage.

It is the same for customer data. No official public record confirming that the attackers stole any account data, IDs, payment data, or passwords. So, it’s too early to call this a data breach.

The date also needs context. Threat intelligence feeds show the listing appeared on September 21. But that doesn’t necessarily mean it’s the date of the attack.

Siinqee Bank’s Profile

With its HQ in Addis Ababa, Siinqee Bank touts itself as a licensed Ethiopian bank by the National Bank of Ethiopia. Siinqee offers many bank and finance services. Its site lists savings and checking accounts, loans, global banking and interest-free banking. It also offers microfinance.

Digital banking is a key part of its service. The bank offers mobile, internet, card, and agent banking. Its mobile service lets users send money and make other payments through an app or USSD. Siinqee also offers digital loans. Its Wabii service covers loans for people, workers and small firms.

The bank had posted some remarkable figures in August. It recorded ETB 178.1 billion in customer deposits, bringing its total assets to ETB 216.2 billion for the 2025/2026 fiscal year.

In addition, Siinqee announced a partnership with Huawei in July. That deal included digital banking services, cloud computing, data governance, and cybersecurity, among others. All these are indications of how active the bank is. They are not proof of validity for Lockbit’s claim.

While the bank’s digital reach makes the LockBit claim worth watching, there’s no evidence that any of its systems suffered a breach. Currently, there’s no official breach confirmation from Siinqee. A review of the bank’s media page didn’t reveal any breach announcements, only a fraud alert from September 16.

Why the Listing Matters

Banks sit on mountains of data and run everyday services that people depend on. So if a real attack hits, things can get messy fast. Attackers can steal customer details, employee details, or even sensitive banking data.

A separate case in Nigeria also highlights the potential scale of banking-related data breach claims. A hacker claimed a breach affecting one million Sterling Bank customers, although that case also requires investigation and verification. These incidents show why customer-data claims involving financial institutions need careful scrutiny before the extent of any breach becomes clear.

In such cases, it is always a prelude to fraud, service outages, and phishing attempts. For now, those are just rumors, not a confirmed cyberattack until official reports from Siinqee or independent researchers surface.

LockBit 5.0 is Active Again

The latest claim comes after LockBit’s comeback following the dismantling of its critical infrastructure by law enforcement in 2024.

The new LockBit 5.0 sprang up last September and has been very active since. According to a Check Point report, the group listed 163 alleged victims in Q1 of 2026. That placed LockBit fourth among ransomware groups tracked by the company during that period.

Researchers say LockBit 5.0 goes after Windows, Linux, and VMware ESXi systems. The group sticks to its old playbook, still running ransomware as a service so affiliates can launch attacks with their resources. And they’re not slowing down.

Recent data shows LockBit 5.0 kept posting new victims throughout September. Its recent listings have included organizations in several industries and countries. That broader activity gives context to the Siinqee Bank listing. It does not, by itself, confirm the Ethiopian bank was successfully breached.

What Happens Next

The next useful sign could come from Siinqee Bank itself, confirming or rejecting the claim. A notice from an Ethiopian regulator could also shed light on the case. Security teams may also look for technical signs of an attack. Those signs could include leaked files, screenshots, file samples, or other data that links the claim to Siinqee.

Researchers will also watch the LockBit leak site. If LockBit later posts files or gives more details, those claims will still need checks. Ransomware groups can post false, old or misleading data.

For bank customers, an official notice from Siinqee would carry more weight than a leak-site post. For now, only a narrow conclusion exists: that LockBit allegedly listed Siinqee Bank. No proof of a successful ransomware attack yet.

No verified public evidence of data theft, file locking, service loss, or a ransom demand. The case remains an unverified ransomware claim as of the time of reporting.

Share this article

You might also like

Hacker Claims $10,000 Android 14–16 Zero-Click Exploit Chain are for Sale

Dark Web Seller Claims $10,000 Android 14–16 Chrome and WebView Exploit Chain for Sale

A dark web operator, xynapse, offers an unconfirmed zero-day exploit chain for Android version 14 to 16 at a price…

September 18, 2026
Hackers Abuse Brevo Cloudflare Key to Push Malware to 100,000 Websites

Hackers Abuse Brevo Cloudflare Key in Supply-Chain Attack Affecting 100,000+ Websites

Attackers used a stolen Brevo Cloudflare API key to change content delivered through Brevo’s network. Visitors saw fake Cloudflare checks…

September 18, 2026
Spain’s Data Regulator Reports First AI Agent Cyberattack Data Breach

Spain’s Data Regulator Reports First Personal Data Breach Carried Out by AI Agent

The AEPD of Spain announced the occurrence of a data breach where an AI agent independently accessed, scouted for vulnerabilities,…

September 18, 2026

About the Author

Jordan Vector

Jordan Vector

Cybersecurity Expert

Jordan is a security researcher and advocate who focuses on making privacy practical. Whether he's explaining how to harden a browser or reporting on the latest surveillance disclosures, his goal is to equip readers with knowledge they can use immediately. Jordan believes that true security begins with understanding the digital landscape.

Comments (0)

No comments.