AYA BANK
bd_1c405a16da1ad174 · schema v1 · pii pii-v1
Full breach record for AYA BANK →Press / market disclosure — not a breach-notification filing
A media or market posting that confirms an incident but carries no breach-notification fields, so compliance clocks aren't assessable. The summary below is extracted from the coverage — verify against the source.
ããã£ã3ãã1⁄4ãï1⁄4¡ï1⁄41ï1⁄4¡éã«ãμã¤ãã1⁄4æ»æãåoå11ç3»ã ̄å1⁄2±é¿ãaãï1⁄4»éèï1⁄41⁄2 | ãããã¬ï1⁄4ãã©ã1. AYA Bank: AYA Bank in Myanmar reported a cyber attack targeting its digital infrastructure. The attack specifically affected an outdated application portal, leading to the alleged leakage of some customer information. The bank confirmed that its core banking systems, including the AYA Pay wallet and card payment systems, remained unaffected. The attack was attributed to a hacker group calling itself 'Lapsus$'. Linked ransomware group: lapsus$.
J jump to incidentP pin to compareR raw source
Incident timeline — mostly unverified
? — ?
Breach window unknown
Jun 23, 2026
Press report
—
Corroborated · see linked filings
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Attack → press
—
Compliance clock
Not assessable
Linked disclosures
Why this link?Ransomware claims (1)
- Leak Sitelapsus$bd_ac40aef90aa4a5772026-06-23Candidate
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.
Source ceiling
- incident type + narrative only (may be machine-translated)
- discovery date
- materiality
- affected count
- data types
- compliance clock
The ✕ fields stay blank until a regulatory filing or victim disclosure lands.
lapsus$
According to ransomware.live, Lapsus$ is an internationally composed data extortion group most active from mid-2021 through 2022, executing high-profile breaches against Microsoft, Nvidia, Samsung, Okta, and Uber by stealing source code and threatening leaks rather than encrypting files; several members — predominantly teenagers — were arrested in the UK.