Summary

Deutsche Bank confirmed this week that it suffered a cybersecurity incident involving a third-party service provider, after the ransomware group known as Unsafe claimed responsibility and began publishing what it alleges are employee database records on a dark web leak site. The bank has not disclosed the identity of the compromised vendor or the full scope of data affected, but the leak site post includes samples of internal employee records.

The incident fits an increasingly common pattern of financial institutions being hit via their third-party supply chain rather than through direct infrastructure attacks. Deutsche Bank joins a long list of major financial firms that have faced breach disclosures stemming from vendor or contractor compromise in 2026. The Unsafe group is a relatively new ransomware-as-a-service (RaaS) operation that has been steadily building its victim list over the past quarter.

No ransom demand amount has been publicly disclosed. Deutsche Bank stated it is “investigating the matter” and that it takes data security “very seriously,” but offered few specifics. The incident is under review by German financial regulators.

Sources

Commentary

Third-party breaches at major banks are becoming a broken record, and yet vendor risk management remains a weak point across the industry. The fact that Deutsche Bank — one of the most heavily regulated financial institutions on the planet — still had a vendor with access to employee database records that lacked sufficient isolation or monitoring is a systemic problem, not a one-off failure. The Unsafe group is new, but the playbook is the same: find a contractor with access, compromise them quietly, and then extort the name-brand customer.

For security teams: your attack surface isn’t just your own infrastructure. Every vendor with access to your data or systems is an extension of your perimeter. Third-party access reviews, contractual security requirements, and continuous monitoring of vendor-sourced connections aren’t nice-to-haves anymore.

By Allan