Qilin Claims Responsibility for Attack on Banco Nacional de Crédito, C.A., and Banco Universal (July 2025)
In July 2025, Banco Nacional de Crédito, C.A., Banco Universal (BNC) suffered a ransomware attack orchestrated by the threat actor Qilin. The incident began with platform disruptions on July 1, 2025, which the bank initially attributed to high transaction volumes and technical issues. However, an X user (@x00x01x01) publicly claimed responsibility for a ransomware attack, mocking the bank and accusing it of hiding money from the Iranian regime. Subsequent reports confirmed that the July 2025 incident was in fact a ransomware attack by Qilin, during which the group allegedly demanded a ransom of $8 million. The exact status of any data breach remains unknown.
Overview
Missing evidence
Impact details
Media outlets and social media report a Qilin ransomware claim against BNC and service outages on the platform around July 2025. Public evidence does not confirm encryption, validated data exfiltration, or specific categories of leaked data.
Classification & severity
- Category
- Malicious code
- Subtype
- Ransomware
- Confidence
- Medium
Public information describes a claim by the Qilin ransomware group against BNC, along with platform availability issues reported around the same time. Data exfiltration and encryption remain unconfirmed.
Severity assessment
High- Functional impact
- Degraded (critical)
- Information impact
- Suspected
- Affected scope
- Organization-wide
- Critical service
- Degraded
- Public confidence
- Moderate
- Recoverability
- Extended
A ransomware claim against a bank, along with the reported online banking outages, justifies a high severity rating, while the data breach and encryption remain unconfirmed.
Timeline
Qilin listed Banco Nacional de Credito, C.A., and Banco Universal as alleged victims.