Too many organisations treat NIS 2 as a policy exercise for the security team. Aaron Smith, Lead InfoSec Consultant at Smarttech247, on why the real shift is leadership accountability, and the three questions every board needs to be able to answer.


A Tier-1 global bank has been publicly listed on a dark web extortion site. Whether or not the claim is verified, the tactics on display are a direct warning to every organisation in financial services.
On July 4, 2026, a threat group operating under the name "Unsafe" posted Deutsche Bank to their dark web data leak site. A countdown timer visible on the post indicated approximately nine days before the group threatens to release or sell the data. This is a textbook double-extortion play: exfiltrate first, then demand payment under threat of public exposure.
Smarttech247 analysts note that Unsafe has been indexed by ransomware-leak monitoring projects, but available public reporting does not conclusively establish it as a standalone ransomware operation or RaaS platform. The claim is unverified. It should be treated as a credible dark web assertion until corroborated by the named organisation, trusted incident reporting, or independent forensic evidence.

Proof-of-compromise screenshots shared by the threat actor point directly at file transfer infrastructure. Command-line outputs showing SFTP activity, internal directory access, service account usage, and the movement of .csv data files suggest the intrusion centred on external-facing Managed File Transfer and SFTP systems.
This is not an isolated tactic. Threat actors have been systematically targeting MFT and SFTP platforms for several years because of the volume and sensitivity of data that flows through them, and because they are frequently internet-exposed, under-monitored, and running on delayed patch cycles.

If your organisation operates in financial services, this is a direct sector threat. File transfer infrastructure is embedded in every bank, insurer, fund manager, and payments processor. Partner gateways, automated transfer accounts, and legacy FTP services are common across the industry, and they are consistently underestimated as an attack surface.
The absence of confirmed Unsafe-specific indicators of compromise means traditional signature-based detection will not catch this. Behavioural visibility across your transfer infrastructure is what matters.
Audit your external exposure
Map every externally accessible SFTP server, MFT platform, file exchange portal, partner transfer gateway, and legacy FTP service. Remove unnecessary internet exposure. Where access is required, restrict it to trusted source IPs.
Review service accounts and SSH keys
Focus on accounts used for automated transfers. Validate ownership, remove unused accounts, rotate credentials and SSH keys where risk is identified, and confirm that service accounts operate on least-privilege access. Check for recently added or modified authorised keys.
Harden and monitor
Patch SFTP and MFT platforms. Disable legacy protocols where not required. Enforce strong authentication for administrative access. Separate inbound, outbound, processing, and archive directories. Enable detailed transfer logging and forward to your SIEM. Apply retention limits to transfer folders and encrypt sensitive files before transfer.
The Unsafe listing may or may not be verified. What is not in doubt is the tactic: external file transfer infrastructure is a high-value, high-yield target, and financial services organisations remain disproportionately exposed. Use this as a forcing function to close those gaps now, before the next countdown timer has your name on it.
We protect your on-premise/cloud/OT environments - 24x7x365