QNB Data Allegedly Offered on Underground Forum, But Claim Remains Unverified

A threat actor is reportedly advertising a database they claim originated from Qatar National Bank (QNB) on an underground cybercrime forum. According to the seller, the alleged database contains information covering the period from 2024 to 2026.

The threat actor claims the dataset may include:

  • User and customer data
  • Transaction information
  • Company activity information
  • Security-related information
  • Government and defence records
  • Police and security information
  • Intelligence-related information

The seller is reportedly inviting potential buyers to request samples of the alleged data.

If authentic, the claimed scope would make the incident potentially more serious than a conventional customer-data leak, particularly because of the alleged government, defence, police and intelligence-related information.

However, the claim has not been independently verified.

Cybersecurity researchers should exercise caution when assessing underground-forum breach claims. Threat actors may exaggerate the sensitivity or value of a dataset to attract buyers, increase their reputation, or even conduct scams against other criminals.

There is also a possibility that information advertised in underground forums may consist of older leaked datasets, publicly available information, or data collected from multiple sources and repackaged as a new breach. Therefore, the claimed QNB connection, the 2024–2026 timeframe, the origin of the data and its contents should not be considered confirmed without additional evidence.

For financial institutions, investigating such claims should go beyond reviewing the forum listing. Security teams can monitor for secondary indicators, including unusual login activity, credential-stuffing attempts, suspicious transactions, and targeted social-engineering attempts against customer-service personnel.

Customers should also remain alert to possible follow-up phishing and impersonation attempts. Criminals may use a reported breach, even an unverified one, to make fraudulent calls or messages appear more convincing.

Customers should never provide passwords, one-time passwords (OTPs), card details, or verification codes to anyone claiming to represent their bank.

The incident highlights an important cybersecurity principle: a serious breach claim deserves attention, but it must be verified before it is treated as a confirmed compromise.