Ransomware

Qilin Claims Responsibility for Attack on Banco Nacional de Crédito, C.A., and Banco Universal (April 2026)

On April 7, 2026, the Qilin (aka Agenda) ransomware group listed Banco Nacional de Crédito, C.A., Banco Universal (BNC) on its data leak site and threatened to publish allegedly stolen information if the bank did not negotiate. The allegedly exposed data—names, passport numbers, email addresses, bank account numbers, dates of birth, and ID numbers—is only visible in samples leaked or claimed by the actor and has not been confirmed by any public source. The bank has not issued any official statement acknowledging the attack. A platform incident reported on March 20, 2026, involved a simultaneous outage at several banks attributed to power outages and is unrelated to this ransomware claim. It is unclear whether the bank suffered any material losses as a result.

Overview

Missing evidence

There has been no official statement from the BNC confirming or denying the incident.There is no public forensic validation or verified sample of the dataset.It has not been confirmed whether encryption, exfiltration, or a physical disruption occurred.

Impact details

Publicly available information about the ransomware supports a claim made by Qilin against BNC. The analyzed public text and images did not provide specific details regarding passports, bank accounts, dates of birth, or identification documents; no official confirmation from BNC has been found, nor has any verified data sample been identified.

Unspecified sensitive data

Classification & severity

Category
Malicious code
Subtype
Ransomware
Confidence
Medium

Public ransomware coverage supports a claim made on the Qilin leak site against BNC. No reviewed source confirms encryption or operational disruption.

Severity assessment

High
Information impact
Suspected
Affected scope
Organization-wide
Critical service
Potential
Public confidence
Moderate
Recoverability
Extended

The Qilin ransomware attack against a bank warrants a high severity rating, but the public sources reviewed did not confirm specific categories of sensitive data, encryption, or service disruption.

Data exfiltration· Claimed Confidentiality

Timeline

Claim

Qilin listed Banco Nacional de Credito, C.A., and Banco Universal as alleged victims.

Evidence & sources

8 sources