-
LockBit 5.0 allegedly added Siinqee Bank to its victim list on September 21, 2026. Public threat feeds now link siinqeebank.com to the group.
-
The claim remains unverified. No public proof reviewed so far shows stolen data, locked files, a ransom demand, or a known way in.
-
Siinqee Bank runs a broad digital banking service in Ethiopia. It offers mobile, online, card, agent and digital loan services.
LockBit 5.0 ransomware group just named Siinqee Bank as one of its new victims. The entry reported appeared on September 21 in threat feeds from several ransomware monitoring platforms.
One tracker lists the entry as ‘lockbit5’ and gives September 21 as the date. Another says LockBit 5.0 claims to have hit the group behind the site. Data from Ransomware.live also recorded LockBit 5.0 publishing siinqeebank.com as a new victim.
It’s, however, worth noting that these feeds report what a ransomware group says on its leak site. They’re not proof that the attack took place.
GalaxyWarden, a service that tracks ransomware claims, marks the Siinqee entry as unverified. It says the claim came from a LockBit leak-site post and has not had outside proof.
No Evidence of Breach or Data Theft
Many important things remain unclarified. No report gives an exact number of stolen data by the attackers. The available reports also do not mention any ransom demand or explain how the attackers may have gained access to the bank.
There is no mention of hit systems either. There is no independent confirmation that LockBit ransomware locked Siinqee’s systems or caused a service outage.
It is the same for customer data. No official public record confirming that the attackers stole any account data, IDs, payment data, or passwords. So, it’s too early to call this a data breach.
The date also needs context. Threat intelligence feeds show the listing appeared on September 21. But that doesn’t necessarily mean it’s the date of the attack.
Siinqee Bank’s Profile
With its HQ in Addis Ababa, Siinqee Bank touts itself as a licensed Ethiopian bank by the National Bank of Ethiopia. Siinqee offers many bank and finance services. Its site lists savings and checking accounts, loans, global banking and interest-free banking. It also offers microfinance.
Digital banking is a key part of its service. The bank offers mobile, internet, card, and agent banking. Its mobile service lets users send money and make other payments through an app or USSD. Siinqee also offers digital loans. Its Wabii service covers loans for people, workers and small firms.
The bank had posted some remarkable figures in August. It recorded ETB 178.1 billion in customer deposits, bringing its total assets to ETB 216.2 billion for the 2025/2026 fiscal year.
In addition, Siinqee announced a partnership with Huawei in July. That deal included digital banking services, cloud computing, data governance, and cybersecurity, among others. All these are indications of how active the bank is. They are not proof of validity for Lockbit’s claim.
While the bank’s digital reach makes the LockBit claim worth watching, there’s no evidence that any of its systems suffered a breach. Currently, there’s no official breach confirmation from Siinqee. A review of the bank’s media page didn’t reveal any breach announcements, only a fraud alert from September 16.
Why the Listing Matters
Banks sit on mountains of data and run everyday services that people depend on. So if a real attack hits, things can get messy fast. Attackers can steal customer details, employee details, or even sensitive banking data.
A separate case in Nigeria also highlights the potential scale of banking-related data breach claims. A hacker claimed a breach affecting one million Sterling Bank customers, although that case also requires investigation and verification. These incidents show why customer-data claims involving financial institutions need careful scrutiny before the extent of any breach becomes clear.
In such cases, it is always a prelude to fraud, service outages, and phishing attempts. For now, those are just rumors, not a confirmed cyberattack until official reports from Siinqee or independent researchers surface.
LockBit 5.0 is Active Again
The latest claim comes after LockBit’s comeback following the dismantling of its critical infrastructure by law enforcement in 2024.
The new LockBit 5.0 sprang up last September and has been very active since. According to a Check Point report, the group listed 163 alleged victims in Q1 of 2026. That placed LockBit fourth among ransomware groups tracked by the company during that period.
Researchers say LockBit 5.0 goes after Windows, Linux, and VMware ESXi systems. The group sticks to its old playbook, still running ransomware as a service so affiliates can launch attacks with their resources. And they’re not slowing down.
Recent data shows LockBit 5.0 kept posting new victims throughout September. Its recent listings have included organizations in several industries and countries. That broader activity gives context to the Siinqee Bank listing. It does not, by itself, confirm the Ethiopian bank was successfully breached.
What Happens Next
The next useful sign could come from Siinqee Bank itself, confirming or rejecting the claim. A notice from an Ethiopian regulator could also shed light on the case. Security teams may also look for technical signs of an attack. Those signs could include leaked files, screenshots, file samples, or other data that links the claim to Siinqee.
Researchers will also watch the LockBit leak site. If LockBit later posts files or gives more details, those claims will still need checks. Ransomware groups can post false, old or misleading data.
For bank customers, an official notice from Siinqee would carry more weight than a leak-site post. For now, only a narrow conclusion exists: that LockBit allegedly listed Siinqee Bank. No proof of a successful ransomware attack yet.
No verified public evidence of data theft, file locking, service loss, or a ransom demand. The case remains an unverified ransomware claim as of the time of reporting.