Critical Unverified

CO-OP URBAN BANK Ransomware Claim by Global Secret Group (Sep 2026)

By Yazoul AI · automated

Unverified dark web claim. This report is based on a post observed on a dark web forum. Yazoul Security has not independently verified the authenticity of this claim.

Leak Site Screenshot

Leak site post claiming CO-OP URBAN BANK LTD data breach

Screenshot captured at time of discovery. Image blurred to protect victim PII.

Leak site post claiming CO-OP URBAN BANK LTD data breach - full size

Claim Summary

The Global Secret Group ransomware operation has allegedly listed CO-OP URBAN BANK LTD, an Indian financial services organization operating the domain indialei.in, on its dark web leak site. According to the threat actor, the attack purportedly occurred on September 10, 2026, and the group claims to have exfiltrated approximately 41.3 GB of data comprising 125,988 files across 14,641 folders.

The victim is described by the threat actor as a bank and finance entity based in India, reportedly generating around $50 million in revenue with an estimated 25 to 50 employees. These figures come solely from the group’s own listing and have not been corroborated by any independent source.

Notably, the leak site entry references a public webpage on the victim’s domain, which may suggest the group is attempting to establish legitimacy by tying its claim to verifiable organizational details. This is a common pressure tactic and does not confirm that any intrusion actually occurred.

Threat Actor Profile

Global Secret Group is a relatively obscure ransomware operation with no significant public research footprint. Unlike well-documented groups such as LockBit, BlackCat, or Cl0p, there is currently no established body of threat intelligence describing this group’s tooling, initial access techniques, or post-exploitation behavior.

The group’s total known victim count remains unknown, and no known tools have been publicly attributed to it. The absence of documented tooling, malware signatures, or YARA rules means defenders cannot currently rely on signature-based detection specific to this actor. Organizations should instead focus on behavioral detection: unusual data staging, large outbound transfers, and abnormal authentication patterns.

Because the group has no verified track record, its credibility cannot be assessed with confidence. Some low-profile groups exaggerate data volumes or recycle previously breached datasets to inflate their reputation.

Alleged Data Exposure

The threat actor claims to hold 41.3 GB of data spanning roughly 126,000 files. The group has not publicly detailed the nature of the data, and no samples, credentials, or download links are referenced in this report for ethical and legal reasons.

If the claim is accurate, a financial institution of this size could plausibly hold customer records, loan documentation, KYC files, and internal communications. However, the specific contents remain entirely unverified. The mention of a public bank information page in the listing may simply reflect publicly available information rather than exfiltrated data.

Potential Impact

For a cooperative bank, even a partially accurate breach could expose customer personally identifiable information, create regulatory scrutiny under Indian banking and data protection frameworks, and damage depositor trust. Financial institutions face heightened obligations around disclosure timelines and customer notification.

That said, the claimed scale should be treated with skepticism. A 41.3 GB dataset is modest for a bank, and the group’s unproven history raises the possibility of exaggeration or misattribution.

What to Watch For

  • Independent confirmation from the organization or Indian regulators
  • Whether the group publishes verifiable data samples (do not seek these out)
  • Any follow-up extortion activity or deadline pressure
  • Reuse of this dataset by other actors or in later campaigns
  • Updates to our /intel/ actor tracking if new research emerges

Disclaimer

This report is based entirely on an unverified claim published on a ransomware group’s leak site. Yazoul Security has NOT independently verified the attack, the data volume, the victim details, or the group’s involvement. Ransomware operators frequently exaggerate claims, recycle data, or misattribute victims to pressure organizations into payment. Nothing in this report should be treated as confirmed fact. Affected parties should conduct their own forensic investigation and consult legal and regulatory counsel.

Share:

Never miss a threat intelligence alert

Get real-time security alerts delivered to your preferred platform.

Related Claims

Never Miss a Critical Alert

CVE advisories, breach reports, and threat intel — delivered daily to your inbox.