Qilin ransomware group announced on July 19 2026 that it had breached Postbank a Deutsche Bank subsidiary extracting 2.3 million customer records. The stolen data includes names account numbers and transaction histories spanning 2019 through 2025. The group demanded 45 million euros in ransom and threatened to auction the data on July 30 2026.
Postbank confirmed the incident on July 20 2026 and stated that core banking systems remained operational. German federal police launched an investigation on July 21 2026 with support from Europol. The attack exploited a zero-day vulnerability in the bank's remote access VPN software patched on July 22 2026.
Qilin has conducted 47 attacks in 2026 targeting healthcare manufacturing and financial services. The group previously claimed responsibility for the June 2026 breach of a major French insurer. Postbank has notified affected customers and offered two years of credit monitoring.
European financial regulators require breach disclosure within 72 hours under DORA rules effective January 2025. Deutsche Bank stock fell 4.2 percent on July 21 2026 following the announcement. Industry groups have called for mandatory ransomware payment reporting across EU member states.
Why this matters
The scale of the Postbank breach highlights persistent vulnerabilities in legacy financial infrastructure despite increased security spending. European banks face mounting regulatory pressure to improve incident response timelines. The incident may accelerate adoption of zero-trust architectures in the sector.
Customers should monitor accounts closely and consider freezing credit reports. Other financial institutions must audit similar VPN configurations immediately. Law enforcement cooperation across borders remains critical to disrupting ransomware operations.
Future attacks are expected to target mid-sized banks with less mature security programs. Organizations should prioritize patching and network segmentation before the next wave of campaigns.