All ransomware incidents
Ransomware group DYSPHOR1A hits CitizensPay
CitizensPay — a financial services target operating in MM has been listed by the DYSPHOR1A ransomware group on 2026-09-05. The information below reflects what the threat actor has publicly claimed on their leak site; the details have not been independently verified.
Incident Report
| Target Organization | CitizensPay |
|---|---|
| Threat Group | DYSPHOR1A |
| Summary | Citizens Pay (also known as CTZPay) is a mobile digital wallet and payment platform in Myanmar powered by Myanmar Citizens Bank (MCB) and Capital Connect Limited. Compromised agent user information — total data size 30 GB. Price range $7,000 to $25,000. Victim domain https://ctzpay.com. |
| Date of Breach | 2026-09-05 |
| Discovery Date | 2026-09-05 |
| Region | MM |
| Target Domain | ctzpay.com |
| Business Sector | Financial Services |
| Severity | MEDIUM |
Claim by DYSPHOR1A
Citizens Pay (also known as CTZPay) is a mobile digital wallet and payment platform in Myanmar powered by Myanmar Citizens Bank (MCB) and Capital Connect Limited. Compromised agent user information — total data size 30 GB. Price range $7,000 to $25,000. Victim domain https://ctzpay.com.
Posted by the DYSPHOR1A threat actor on its public leak site. This is the group's own statement and has not been independently verified by HackerFeeds.
Sources
Disclaimer
HackerFeeds does not engage in the exfiltration, downloading, taking, hosting, viewing, reposting, or disclosure of any stolen information. All breach data reported here is sourced from publicly available threat intelligence feeds for awareness purposes only.

