Alleged Sale of DFCC Bank, Cargills Bank,
and Sri Lanka Customs Data

A threat actor posted to a public forum claiming access to customer data from DFCC Bank and Cargills Bank, and employee records from Sri Lanka Customs. Bank account balances belonging to high-balance customers were released publicly as a freebie sample, without payment, at the time of the original post. A 14-day response deadline was then issued. When no response came, a Russian-language post confirmed the broader dataset was sold on August 5, 2026, including alleged credit card numbers, access to a command and control system, and exploits to bypass bank security controls.

SOLD Reported Transaction
Status
CONFIRMED Balance Data
Publicly Released
UNVERIFIED Full Dataset
Authenticity
Important Caveat The claims in this post originate from a threat actor on a forum. The authenticity of the alleged data, the scope of any intrusion, and the legitimacy of the sale have not been independently verified. This report documents what is publicly observable and stated by the threat actor. Readers and affected institutions should treat the claims seriously while recognizing they are unverified.

What Is Publicly Known

A post appeared on a public cybercrime forum claiming the poster had active access to systems belonging to DFCC Bank, Cargills Bank, and Sri Lanka Customs. The post was written in English and offered the dataset for sale through an escrow service, a mechanism used in criminal marketplaces to guarantee delivery of goods before payment is released.

The post included a freebie sample. Bank account balances belonging to high-balance customers were released publicly as part of this sample, without payment. This is the confirmed data disclosure: balance data was made available before any sale took place. The specific individuals affected are not identified in this report.

A 14-day deadline was issued to the named institutions. The post stated that if no interested parties responded, data samples would be published in stages and sent to bulk email lists of companies across Sri Lanka. The deadline passed without any publicly observable response from the named institutions.

On August 5, 2026, a follow-up post in Russian confirmed the transaction was complete. The sale was described as covering credit card numbers, access to a command and control (C&C) system, and exploits to bypass bank security controls. The post stated the project was closed.

Timeline

Before Aug 5
Data Disclosed
Bank Balance Data Released Publicly Without Payment
Bank account balances of high-balance customers released as a freebie sample attached to the original forum post. This is the confirmed public disclosure: actual financial data made available before any sale, at no cost, to establish credibility.
Before Aug 5
Forum Post
Initial Claim Published
Threat actor posts to public forum claiming access to DFCC Bank, Cargills Bank, and Sri Lanka Customs data. Dataset offered for sale via escrow. 14-day deadline issued to named institutions.
14-Day Window
No Response
Deadline Passes
No publicly observable response from DFCC Bank, Cargills Bank, or Sri Lanka Customs. No public acknowledgment of the threat or any reported breach from the named institutions during this period.
Aug 5, 2026
Sale Confirmed
Sale Reported Complete
Russian-language post confirms transaction finalized via escrow service. Alleged contents transferred: credit card numbers, C&C system access, exploits to bypass security controls. Poster states project is closed.
Aug 26, 2026
This Report
SLEXPOSE Incident Report Published
This report published based on publicly observable forum posts and sale confirmation. No response or statement from named institutions at time of publication.

Named Targets

$
DFCC Bank
Claimed: Complete copy of customer data
$
Cargills Bank
Claimed: Complete copy of customer data
G
Sri Lanka Customs Department
Claimed: Government majority employee factsheet (described as a freebie in the post)

What the Sale Confirmation States

The sale confirmation was posted in Russian. Below is the translated content as published, reproduced for documentation purposes.

Sale Confirmation (translated from Russian, Aug 5, 2026)
"Please do not contact regarding samples. The final sample is shown below. It is hidden (cannot be shown per agreement). The agreement for the sale of the banking data set through an escrow service, concluded yesterday, has been finalized. Credit card numbers, access to the C&C system, and exploits to bypass protection: all transferred. Project closed."

The use of Russian in the confirmation post is consistent with the actor's apparent origin or operating language. The reference to a C&C (command and control) system is significant: C&C systems are used to maintain persistent access to compromised infrastructure. If the claim is accurate, the buyer received not just data but active tools to continue operating within the affected systems.

What Is Known vs What Is Claimed

Independently Observable

Forum post exists and is publicly visible
Sale confirmation post exists and is publicly visible
Three institutions named in the public post
14-day deadline issued and passed
Bank account balances of high-balance customers were released publicly as a freebie, without payment
Transaction reported as completed via escrow on Aug 5
No public statement from named institutions at time of publication

Threat Actor Claims (Unverified)

Customer data is genuine and complete
Active access to bank systems via C&C
Exploits capable of bypassing bank security controls
Credit card numbers included in dataset
Customs employee records included
All material successfully transferred to buyer

Why C&C Access Claims Are Significant

Standard data breach incidents typically involve exfiltration of historical data: records pulled from a database and sold. The C&C access claim, if accurate, describes something different: the sale of ongoing access to the compromised infrastructure. A buyer receiving C&C access would retain the ability to issue commands, exfiltrate additional data, or move laterally within the network.

This distinction matters for incident response. If the claim is accurate, closing the transaction does not end the incident. The buyer now holds access tools. The appropriate response from any affected institution is to assume the network is still compromised until a full forensic investigation establishes otherwise.

Note on Data Authenticity Threat actors on criminal forums routinely exaggerate the scope and authenticity of data they sell. Freebie samples are sometimes fabricated or sourced from previous unrelated breaches. This report does not confirm the data is genuine. It documents that the claims are public, the sale was reported as complete, and the named institutions have not publicly responded. Authenticity can only be determined by the affected institutions through internal investigation.

What Affected Institutions Should Do

Based on the publicly stated claims, affected institutions should treat this as a credible threat requiring immediate investigation, without waiting for independent confirmation of the data's authenticity.

For DFCC Bank and Cargills Bank: engage an incident response team to investigate potential unauthorized access to customer data systems. Audit authentication logs for anomalous access. Review network traffic for C&C communication indicators. Notify the Central Bank of Sri Lanka and CERT.LK. Consider whether customer notification obligations apply under applicable law.

For Sri Lanka Customs: investigate whether employee records were accessed. Review access logs for HR or personnel systems. Notify CERT.LK and the relevant government cybersecurity authority.

For affected customers and employees: if you hold accounts at DFCC Bank or Cargills Bank, monitor for unauthorized transactions and consider placing fraud alerts. If you are a Sri Lanka Customs employee, be alert to phishing attempts using your work information.

Contact for Affected Institutions

CERT.LK (Sri Lanka Computer Emergency Readiness Team) can be reached at incidents@cert.gov.lk for incident reporting and coordination assistance.

The Central Bank of Sri Lanka's Financial Intelligence Unit can be reached through the CBSL website for financial crime reporting.

Editorial Note This report does not publish the threat actor's contact handles, data samples, or any information that would facilitate further harm. The forum post and sale confirmation are public records documented here for journalistic and public interest purposes. SLEXPOSE does not endorse, facilitate, or profit from cybercriminal activity.