Qilin Claims Responsibility for Attack on Banco Nacional de Crédito, C.A., and Banco Universal (April 2026)
On April 7, 2026, the Qilin (aka Agenda) ransomware group listed Banco Nacional de Crédito, C.A., Banco Universal (BNC) on its data leak site and threatened to publish allegedly stolen information if the bank did not negotiate. The allegedly exposed data—names, passport numbers, email addresses, bank account numbers, dates of birth, and ID numbers—is only visible in samples leaked or claimed by the actor and has not been confirmed by any public source. The bank has not issued any official statement acknowledging the attack. A platform incident reported on March 20, 2026, involved a simultaneous outage at several banks attributed to power outages and is unrelated to this ransomware claim. It is unclear whether the bank suffered any material losses as a result.
Overview
Missing evidence
Impact details
Publicly available information about the ransomware supports a claim made by Qilin against BNC. The analyzed public text and images did not provide specific details regarding passports, bank accounts, dates of birth, or identification documents; no official confirmation from BNC has been found, nor has any verified data sample been identified.
Classification & severity
- Category
- Malicious code
- Subtype
- Ransomware
- Confidence
- Medium
Public ransomware coverage supports a claim made on the Qilin leak site against BNC. No reviewed source confirms encryption or operational disruption.
Severity assessment
High- Information impact
- Suspected
- Affected scope
- Organization-wide
- Critical service
- Potential
- Public confidence
- Moderate
- Recoverability
- Extended
The Qilin ransomware attack against a bank warrants a high severity rating, but the public sources reviewed did not confirm specific categories of sensitive data, encryption, or service disruption.
Timeline
Qilin listed Banco Nacional de Credito, C.A., and Banco Universal as alleged victims.