KBZ Bank and AYA Bank Were Both Named on Ransomware Leak Sites in 2026 — Here’s What’s Actually Confirmed

Over a roughly three-month span in 2026, two of Myanmar’s largest private banks each turned up on a criminal extortion group’s leak site. In June, the group LAPSUS$ claimed to have stolen more than 120GB of data from AYA Bank and threatened to publish it unless a ransom was paid by July 8, according to the UK cybersecurity outlet teiss.co.uk on June 29, 2026. AYA Bank itself acknowledged an attack days earlier, according to Burma News International (BNI) on June 26, 2026. Then, on August 24, 2026, a separate group calling itself “The Crew” listed both KBZ Bank and AYA Bank on its own leak site, according to two posts from threat-intelligence outlet GalaxyWarden — one on KBZ Bank and one on AYA Bank, both dated August 24, 2026. KBZ Bank has publicly denied any breach, per a report from news.myantrade.com on August 26, 2026. As far as we could find, AYA Bank has not publicly responded to the August claim.

Myanmar Tech Press has not previously covered either incident. What follows is not breaking news — the most recent event is now more than a month old — but a look at a pattern that, as far as we can tell, Myanmar’s tech press hasn’t laid out side by side: two of the country’s biggest banks, two different criminal groups, two very different levels of confirmation, all within a single year.

A Three-Month Timeline: LAPSUS$ in June, The Crew in August

The first incident began around June 23, 2026, when the ransomware-tracking database ransomware.live logged an entry for AYA Bank attributed to LAPSUS$. The entry lists specific figures: 16 compromised employee accounts, 297 compromised user credentials, 92 third-party employee credentials, and 27 external attack-surface vulnerabilities, alongside a message from the group reading, in part, “Full dump and PII data’s. If AYA Bank dont contact us or pay the ransom we will start sale.” Teiss.co.uk’s June 29 report put the claimed data volume at more than 120GB and noted a July 8 deadline for payment before the group said it would publish the data.

Roughly two months later, on August 24, 2026, a different, apparently unrelated group — The Crew — added both KBZ Bank and AYA Bank to its own leak site. GalaxyWarden’s separate write-ups on each listing do not specify what data The Crew actually holds for either bank, and both note that the listing itself had not been independently confirmed. News.myantrade.com’s August 26 report adds one more detail: it says The Crew posted a sample on X (formerly Twitter) that it claimed came from KBZ Bank, including roughly ten bank user accounts, some iBanking accounts, email addresses, usernames, and passwords — a claim the report explicitly labels unverified. The report does not attribute any specific data count to AYA Bank.

What AYA Bank Actually Confirmed in June — and What It Didn’t

Of the two incidents, the June one is the better-documented, because AYA Bank itself spoke about it. According to BNI’s June 26 report, AYA Bank confirmed that an “old application portal” had been compromised, but said the affected system was not connected to its core banking platform, AYA Pay, or its card systems, and that regular internet and mobile banking services remained available throughout. Teiss.co.uk’s later report repeats the same distinction: the breach was contained to a legacy portal, not the systems customers use day to day.

That is a meaningful qualification, and it’s worth stating plainly rather than letting “AYA Bank hacked” stand on its own: the bank has confirmed a breach of a specific, older system, while denying that its core banking, payment, or card infrastructure was touched. Whether that portal held customer PII, and how much, is not something we could independently verify beyond the figures in the ransomware.live entry — which come from a third-party tracking database summarizing the attacker’s own claims, not from AYA Bank.

KBZ Bank’s Denial Deserves Top Billing, Not a Footnote

The August incident is different in an important way: KBZ Bank did not confirm anything. According to news.myantrade.com’s August 26 report, KBZ Bank stated that its latest cybersecurity review found no evidence of a breach or hacking activity. That denial is the single most load-bearing fact in this story, and it belongs at the top of any accurate account of what happened in August — not buried under the more dramatic claim that a bank was “hacked.”

AYA Bank’s position on the August listing is murkier, but for a different reason: it hasn’t taken one, at least not publicly. As far as we could find in the available reporting, AYA Bank has not issued a statement addressing The Crew’s August claim, either confirming, denying, or clarifying it. That silence is not itself evidence of anything — companies decline to comment on extortion claims for all sorts of reasons, including advice from cybersecurity counsel — but it does mean the August AYA Bank listing sits in a different evidentiary category than the June one: unconfirmed by the bank, unconfirmed independently, and unresolved as of this writing.

Why Being Named on a Leak Site Is Not the Same as Being Breached

This is worth stating directly because it’s easy to skip past: appearing on a ransomware or extortion group’s leak site is a claim made by criminals seeking payment or publicity, not proof of a breach. These groups have an incentive to list well-known names — a big bank’s name draws more attention to the leak site than an obscure company’s — and relatively little cost if the claim turns out to be exaggerated or false. Security researchers who track these sites routinely flag listings as “unverified claims” until data actually surfaces and can be checked against real records, which is exactly the label news.myantrade.com’s report applies to The Crew’s August claim.

None of this means the claims should be dismissed. LAPSUS$’s June claim was followed by an actual acknowledgment from AYA Bank, which shows that at least one of these listings corresponded to a real (if limited, by the bank’s account) intrusion. But it does mean that a bank’s name showing up on a leak site is the start of a question, not the answer to one — and KBZ Bank’s denial in August is a legitimate part of that record, not something to be waved aside because a denial is less newsworthy than a hack.

The Open Question Nobody’s Announcement Answers: Timing Against the CBM’s Overseas Access Block

On August 28, 2026, Myanmar’s central bank, the CBM, reportedly ordered banks to block overseas access to mobile payment apps including K-Pay (KBZPay), AYA Pay, and Wave Money — a report Myanmar Tech Press covered on September 9, 2026. As that article noted, the order was reported rather than officially announced, and it was not confirmed whether the block was actually switched on. The reported start date came four days after The Crew’s August 24 leak-site listings of KBZ Bank and AYA Bank.

We want to be careful here: we have seen no evidence, official or reported, tying the reported CBM order to either the June LAPSUS$ claim or the August The Crew claim. The CBM has not publicly explained the order at all; the motive described by observers in the original reporting was cutting off financial channels to the anti-junta resistance, not cybersecurity. The proximity in timing is the only thing connecting them in the public record, and proximity is not causation. We’re flagging it as an open question worth watching, not as something we can currently answer.

What This Means for KBZPay and AYA Pay Users

None of the reporting we reviewed indicates that KBZPay or AYA Pay customer accounts were compromised in either incident; AYA Bank specifically said its payment platform was unaffected by the June portal breach, and KBZ Bank has denied any breach at all. Still, a few basic precautions are worth restating for anyone using either service, independent of whether these specific claims turn out to be founded:

  • Don’t reuse passwords. If your KBZPay or AYA Pay password is the same one you use elsewhere, a breach at an unrelated service could still expose your banking login. Use a unique password for financial apps.
  • Be skeptical of calls, texts, or messages referencing a “data leak.” After any bank’s name appears in leak-site news, scammers often follow up with phishing calls or SMS claiming to “verify your account” — this is a well-worn pattern that doesn’t require an actual breach to have happened.
  • Only use official apps and websites. Don’t click links in unsolicited messages claiming to be from KBZ Bank or AYA Bank; go directly to the official app or a manually typed URL instead.
  • Enable any available two-factor or biometric authentication on your mobile banking app if you haven’t already.

Frequently Asked Questions

Were KBZ Bank and AYA Bank actually hacked?
AYA Bank acknowledged a breach of an old application portal in June 2026, which it said was not connected to core banking, AYA Pay, or card systems. KBZ Bank has denied any breach following the August 2026 leak-site listing, saying its own security review found no evidence of intrusion. AYA Bank has not publicly addressed the August claim as far as we could find.

What is LAPSUS$?
LAPSUS$ is the name used by the extortion group that claimed responsibility for the June 2026 AYA Bank incident, according to teiss.co.uk and the ransomware-tracking database ransomware.live.

What is “The Crew”?
The Crew is a separate extortion group that listed both KBZ Bank and AYA Bank on its leak site on August 24, 2026, according to GalaxyWarden’s reporting. It is a different group from LAPSUS$, and its August claims about the two banks have not been independently confirmed.

Is my money at risk if I use KBZPay or AYA Pay?
Based on the public statements available, AYA Bank has said its payment platform was not affected by the June portal breach, and KBZ Bank denies any breach occurred in August. There is no confirmed evidence that either app’s transaction systems were compromised. General account-security precautions are still worth following regardless.

Is this connected to the CBM blocking overseas access to mobile payment apps?
We haven’t found any evidence connecting the two. The CBM reportedly ordered banks to block overseas access to K-Pay, AYA Pay, and Wave Money from August 28, 2026, four days after The Crew’s leak-site listings, but the order was never officially announced, no statement has linked the two, and the timing alone isn’t proof of a connection.

Where This Leaves Things

Strip away the leak-site branding and criminal marketing language, and what’s left is this: one confirmed, limited breach of a legacy AYA Bank system in June, with the bank’s core services reportedly unaffected; and one unconfirmed, denied claim against KBZ Bank in August, paired with a claim against AYA Bank that the bank has not addressed. Both are worth tracking, and neither should be flattened into a single “Myanmar banks hacked” headline. If new information changes any of this — a bank statement, a data sample that can be checked, or a documented tie to the CBM’s access restrictions — we’ll update accordingly.


Sources: teiss.co.uk, “LAPSUS$ targeted Myanmar’s AYA Bank, stole 120GB of banking data” (June 29, 2026), https://www.teiss.co.uk/news/lapsus-targeted-myanmars-aya-bank-stole-120gb-of-banking-data-17726 · Burma News International, “Myanmar’s AYA Bank acknowledges cyberattack after hacking group claims data breach” (June 26, 2026), https://www.bnionline.net/en/news/myanmars-aya-bank-acknowledges-cyberattack-after-hacking-group-claims-data-breach · ransomware.live, AYA Bank / LAPSUS$ entry (detection timestamp June 23, 2026), https://www.ransomware.live/id/QVlBIEJBTktAbGFwc3VzJA · GalaxyWarden, “KBZ Bank” breach listing (August 24, 2026), https://www.galaxywarden.com/blog/breach/kbz-bank-the-crew-2026-08 · GalaxyWarden, “AYA Bank Myanmar” breach listing (August 24, 2026), https://www.galaxywarden.com/blog/breach/aya-bank-myanmar-the-crew-2026-08 · news.myantrade.com (August 26, 2026), https://news.myantrade.com/archives/49790 · Myanmar Tech Press, “CBM Blocks Overseas Mobile Payment Apps” (September 9, 2026), https://en.myanmartechpress.com/cbm-blocks-overseas-mobile-payment-apps/