CR2 Listed by avoslocker Ransomware Group
If you are a customer of CR2, here’s what is being claimed, and what it would mean for you.
CR2 is an Irish-owned banking software company which provides mobile, internet and ATM financial service technology to more than 100 retail banks across Africa, the Middle East and Asia. Headquartered in Dublin, Ireland, the company has offices in Dubai, London, Cairo, Amman, Bengaluru, Lagos, Johannesburg, Singapore and Perth. Its customers include ANZ, Barclays, Standard Chartered, Botswana Savings Bank, Jordanian Bank al Etihad,pan-African bank Orabank, and Nigeria’s Access Bank plc and Diamond Bank. 500 GB+ Data includes: - Sources to all products ever developed including Ban
— from Avoslocker’s own leak-site posting. This is the group’s claim, quoted verbatim; it is not GalaxyWarden’s reporting and has not been independently verified.
Editor’s note: The claims described below originate from a ransomware group’s leak-site posting and have not been independently verified by GalaxyWarden. A listing of this kind is an assertion made by the group during an extortion attempt. It is not evidence that a breach occurred, and we report it as a claim rather than as a finding.
Assessing CR2 as a vendor?
Check your own domain — free, no cardEnter a work email. We count the addresses at that domain sitting in the leaked-data corpus, and how many arrived with a password.
Were you personally caught up in this? Run a free 15-second personal scan.
On December 26, 2022, Irish banking-software provider CR2 appeared on the leak site of the AvosLocker ransomware group. The listing states that internal files were exfiltrated during a ransomware attack and that more than 500 GB of data had been taken. The company, which supplies mobile, internet, and ATM technology to over 100 retail banks across Africa, the Middle East, and Asia, has not published a public breach notification quantifying affected records or detailing precisely which customer information was included.
Primary Disclosure Details
The AvosLocker leak page, archived via ransomware.live, lists CR2 as a victim and claims the attackers extracted source code for all products the company has ever developed, along with other internal files. The disclosure does not specify the exact number of individuals whose data may have been exposed, nor does it list particular categories such as customer account numbers or personal identifiers. It simply states that 500 GB+ of data was obtained following a ransomware deployment. CR2 itself has not released a detailed regulatory filing or customer notification that would clarify the scope, leaving the full extent of the breach unknown to the public.
Why This Matters for You and Your Family
If you hold an account with any bank that uses CR2’s platform, your financial activity may have been caught in the exfiltration. Banks served by CR2 include ANZ, Barclays, Standard Chartered, Botswana Savings Bank, Jordanian Bank al Etihad, Orabank, Access Bank, and Diamond Bank. Even though the leak-site listing does not itemize every record type, the theft of complete product source code and internal files raises the possibility that configuration data, integration details, or customer reference information traveled with it. For ordinary customers this translates into elevated risk of account takeover, phishing campaigns tailored to specific banking apps, and long-term identity abuse that can affect credit, loans, and day-to-day finances for you and your family.
Advertisement
BATECH StudioWe build it.We run it.Web apps, AI pipelines and internal tools — under your brand, not ours.Tell us what you need →
BATECH Studio and GalaxyWarden share common ownership.
Doxxing and Identity-Chain Risks
Ransomware operators rarely stop at financial data. When source-code repositories and internal directories are taken, attackers gain email addresses, employee usernames, partner contact lists, and sometimes customer metadata. These pieces form the starting points for doxxing chains that link gaming handles, social-media accounts, phone numbers, and home addresses. A credential exposed in one breach can be tested across personal email, mobile-banking apps, and children’s online gaming profiles. The result is a single point of failure that can cascade into full identity compromise, harassment, or targeted fraud against every member of a household.
AvosLocker’s Known Track Record
Public reporting attributes AvosLocker’s first significant campaigns to mid-2021. The group has since hit hospitals, municipalities, manufacturers, and technology providers across multiple continents. Their typical playbook begins with initial access gained through remote-desktop services or compromised credentials, followed by exfiltration of sensitive files before ransomware is deployed. AvosLocker then publishes a sample of stolen data on their leak site and demands payment, threatening full publication or sale of the remaining archive if the victim does not meet the deadline. The CR2 listing follows this pattern exactly, with the group posting proof of access and a volume claim while withholding the bulk of the material pending ransom.
What to do
- Rotate any password you have reused at CR2 customer banks or related financial services, then enable 2FA through an authenticator app rather than SMS.
- Run a DoxxScan to map every link between your emails, phone numbers, handles, and real-world identity, with cleanup of exposed records.
- Enable continuous DoxxScan monitoring across 13.1B+ breach records and 100+ platforms so the next leak that touches you or your family is flagged within hours.
- Cover the entire household with DoxxScan family protection, which extends to dependents and children’s gaming accounts that often chain back to the same address or parent credentials.
- Let remediation specialists handle takedown requests across data brokers and extortion sites on your behalf while you focus on securing day-to-day accounts.
The CR2 incident shows once again that third-party software vendors can become gateways to customer data at scale. Staying ahead requires more than checking a single breach list; it demands ongoing visibility and expert help. DoxxScan by GalaxyWarden delivers continuous monitoring across 13.1B+ breach records and 100+ platforms, AI-powered identity-chain mapping, and hands-on remediation by specialists, with household coverage that includes children’s gaming accounts vulnerable to the same credential-stuffing waves. Start your DoxxScan trial today and close the gaps before the next wave of extortion sites lists your information.
What the free scan actually returns
Found on people-search siteswe remove these
These listings are live, public, and legal to remove — and removing them is what we do.
Found in breach recordsverifiedreported — unverified
Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.
Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.
For security and vendor-risk teams: a staff address in a leak does not mean you were breached — it usually means a third party was. We monitor a domain against 13.1B+ leaked records and tell you when one of your people appears. See what we would check →
Report details & sourcing
Related breaches
Volktek Listed by thegentlemen Ransomware Group
volktek.com zoominfo.com/c/volktek-corp/161873991 Volktek is a leading Taiwanese manufacturer establ…
The Cecilian Bank Listed by Storm Ransomware Group
The Cecilian Bank is an FDIC-insured financial institution that offers a wide range of personal and …
Tower Insurance Listed by coinbasecartel Ransomware Group
Tower Insurance is a New Zealand-based insurance company offering a range of personal and business i…