Skip to content
Braincap
← All articles

Ransomware attack at Techventures Bank (former Banca Feroviară): what is confirmed and what is not

by Claudiu Hulea · IT Management Consultant

Illustration of a ransomware attack on a bank, with a DNSC-style response — encrypted systems and an ongoing investigation

On 2 August 2026, DNSC announced it had been notified of a ransomware attack at Techventures Bank S.A. — the former Banca Comercială Feroviară. Beyond that confirmed fact, almost everything is, officially, still unknown. This article separates exactly what we know from what we do not — because, in a banking incident, speculation does more harm than silence.

What DNSC confirmed

The DNSC statement, in its official form (translated):

“The National Cyber Security Directorate (DNSC) was notified on 02.08.2026 of a cybersecurity incident registered by Techventures Bank S.A., consisting of a ransomware attack. At the company’s request, a team of DNSC specialists is providing support in this case for mitigating the incident and investigating the attack.”

So, with certainty:

  • The entity: Techventures Bank S.A., the former Banca Comercială Feroviară S.A. (registration ID 25263452, Bucharest).
  • The type: ransomware (encryption of files/systems, usually with a ransom demand).
  • The response: DNSC is assisting with mitigation and investigation, at the bank’s request — analyzing digital evidence, access mechanisms and any exploited vulnerabilities.
  • Notification date: 2 August 2026.

Update (6 August): the RansomHouse group claims the attack

On 6 August 2026, the extortion group RansomHouse listed Techventures Bank on its leak site (a listing indexed by the ransomware.live monitoring platform), describing the target as “a Romanian universal bank, rebranded from Banca Comercială Feroviară”. The group cites the attack date as 3 August and references a leak screenshot.

It matters how this is read:

  • It is the group’s claim, not a confirmation. A leak-site listing is a pressure/extortion tool — its existence confirms that someone claims the attack, not that any displayed data is real, complete or authentic.
  • The bank and DNSC have not confirmed the attribution to RansomHouse, nor the content or scope of any exfiltrated data.
  • RansomHouse often operates through data theft and extortion (“name-and-shame”), not necessarily encryption — which does not change the fact that DNSC classified the incident as ransomware.

In short: we now have a claimed attribution (RansomHouse), but still officially unverified. Everything below remains valid.

Update (8 August): the digital services appear to be back

As of 8 August 2026, the bank’s public website (techventures.bank) and its internet-banking portal (ib.techventures.bank) are reachable again and render a normal login page, with no maintenance or outage banner. The signal suggests an at least partial return of the digital services for customers.

Two clarifications, to stay with the facts:

  • This is an observation of public availability, not a confirmation. A portal that responds does not prove that all internal systems have been fully restored — only that the customer-facing interface is reachable again.
  • Neither the bank nor DNSC has officially communicated a return, the scope of the restoration, or the status of the investigation. When an official position appears, we will add it here, attributed.

What is NOT known (and why we do not invent it)

At the time of the communication, the following were not disclosed:

  • the number of affected systems;
  • the duration of any operational disruptions;
  • the existence of financial losses;
  • whether attackers exfiltrated data before encryption (double extortion) or whether customer data was compromised;
  • the ransom amount demanded;
  • official confirmation of the attribution — RansomHouse has claimed the attack (see above), but the authorities have not publicly confirmed that attribution, and the authenticity of the claimed data remains unverified;
  • the concrete impact on digital platforms, internal applications or customer services.

The bank has not published a statement of its own with technical detail. Any claim about “stolen customer data” or “affected accounts” is, at this point, speculation — not fact. The investigation is ongoing, and the conclusions come from it, not from headlines.

Why it matters: a bank is a DORA and NIS2 entity

Whatever details emerge, the structure of the problem is clear and useful for any regulated organization.

An EU bank is a financial entity under DORA (the Digital Operational Resilience Act, in force since 17 January 2025) and also falls under NIS2. A ransomware attack on a bank is exactly the scenario these frameworks exist for:

  • Mandatory incident reporting — notifying the authority (here, DNSC) is not a PR gesture but a compliance obligation. That a notification happened is a sign the mechanism worked.
  • Operational resilience — DORA requires the institution to be able to continue and recover critical operations after a severe ICT incident, not merely to prevent it.
  • Testing and preparedness — response plans, backups and recovery scenarios that are rehearsed, not just documented.

Ransomware does not ask how big you are. It only asks whether your backup is isolated from the attacker and whether you know, within minutes, what you restore and how.

Our recommendations

If you are a regulated institution or a company that cannot afford a day without systems, here is what directly reduces this kind of risk:

  • Isolated backup + tested recovery. Offline/immutable copies, separate from the domain production runs on, plus a real restore exercise with a measured time objective (RTO/RPO). A backup you have never restored is an assumption, not a plan. Part of the security audit.
  • Reducing the ransomware surface. Phishing-resistant MFA, segmentation, least privilege, patching on exposed assets — the combination that stops lateral movement. See also what NIS2 requires in Romania.
  • Detection and a response plan. Monitoring and periodic review catch encryption in progress and anomalous activity before everything is locked; a rehearsed incident plan shortens the hour in which everything is decided.
  • Testing the defense before the incident. A security test shows where an attacker would get in and how far they would reach — exactly what you want to know before, not during, an incident.

Want to know how prepared you are for a ransomware scenario? Get in touch and we start with an audit.


The confirmed statements come from the public DNSC communication and the press that relayed it. The attribution claim belongs to the RansomHouse group, listed on its leak site and indexed by ransomware.live — it is an attackers’ allegation, not confirmed by the bank or the authorities. The incident details are under investigation; this article should be read in that context.

Frequently asked questions

What has been officially confirmed?

According to DNSC (Romania's National Cyber Security Directorate), it was notified on 2 August 2026 of a cybersecurity incident at Techventures Bank S.A. — a ransomware attack — and a team of DNSC specialists is supporting mitigation and investigation at the bank's request. Techventures Bank S.A. is the former Banca Comercială Feroviară S.A.

Was customer data affected?

Unknown. At the time of the communication, neither DNSC nor the bank stated whether the attackers exfiltrated data before encryption, how many systems were affected, whether there were service disruptions, or whether customer data was compromised. Any claim to that effect would be speculation — the investigation is ongoing.

Who carried out the attack?

On 6 August 2026, the extortion group RansomHouse listed Techventures Bank on its leak site (indexed by the ransomware.live monitoring platform), claiming the attack and citing 3 August as the date. Note: this is the group's claim, with a referenced leak screenshot, but it is NOT confirmed by the bank or DNSC — the authenticity and scope of any data remain unverified. The authorities have not officially communicated an attribution.

What should a bank or company learn from this?

A bank is a regulated entity under DORA and NIS2 — ransomware is exactly the scenario those frameworks exist for: mandatory incident reporting (which happened here, the DNSC notification), operational resilience, and the ability to recover. Real preparedness means isolated/immutable backups, tested recovery, an incident response plan, segmentation, phishing-resistant MFA, and monitoring.

Related articles