Back to all incidents

Deutsche Bank — third-party platform breach, Unsafe extortion claim

Extortion group Unsafe listed Deutsche Bank and leaked alleged employee records; the bank attributes the breach to a German third-party marketing platform, not its network.

Target
Deutsche Bank — third-party platform breach, Unsafe extortion claim
Date public
4 July 2026
Sector
Financial Services
Attack type
Data Breach
Threat actor
Unsafe
Severity
High
Region
Germany

In early July 2026 the extortion group Unsafe added Deutsche Bank to its dark-web leak site, publishing what it described as employee database records as proof of access. The advertised fields were specific: employee email addresses, password hashes, physical addresses and internal database extracts. Unsafe, first seen in December 2022, went quiet through 2024 and 2025 before resurfacing in 2026 with a run of double-extortion listings against large brands.

Deutsche Bank’s response drew a firm boundary. The bank said the incident did not involve its own corporate network but affected a third-party company in Germany that runs a marketing and incentive platform for its sales partners. Reporting has noted a degree of tension in the bank’s account, with one line stating its internal investigation had found no evidence of a third-party compromise affecting its corporate network. What is not yet public is the figure that matters: how much data the platform held, how many sales partners it covered, and whether the leaked password hashes were salted or trivially crackable.

The defender angle is the one every UK and European financial-services firm is now living under DORA. A sales-incentive platform is precisely the sort of low-visibility supplier that rarely reaches the critical-third-party register, yet it held credentials and personal data tied to the bank’s own people. Whether the platform was segmented from anything that could reach bank systems, and whether those hashes were built to survive exposure, are board-level third-party questions rather than procurement ones. Scope, attribution detail and the vendor’s identity remain unconfirmed; this entry will be updated as the picture firms up.

Sources

Back to all incidents