24 Apr 2026

Standard Bank Rootboy breach + Bitwarden supply chain + Claude Desktop manifests

This week broke my trust in digital infrastructure a little more than usual.

Standard Bank: Rootboy spent 3 weeks undetected inside their systems. 1.2TB dumped. Your ID number, passport, credit card details — publicly available because they wouldn't pay 1BTC (~R1.2m).

Bitwarden CLI: compromised via a hijacked GitHub Action, malicious npm package live for 90 minutes stealing SSH keys, cloud credentials, crypto wallets.

Separately, Anthropic/Claude Desktop silently installing native messaging manifests into browsers you haven't even installed yet — without disclosure.

Three separate issues (That I know of). One week.

The instinct is to go full tin-foil — cash only, offline KeePass vault, disconnect everything. But here's the uncomfortable truth: the Standard Bank breach exposes your ID number regardless of how you bank. You can't opt out of data an institution already holds.

The real problem isn't the attacks. It's that there's no meaningful consequence for the institutions when they fail. GDPR gives European regulators actual teeth. POPIA is still largely untested in enforcement. Standard Bank will issue statements, cooperate with authorities, and move on. Customers get... advice to register with SAFPS.

What does accountability actually look like here? Because "remain vigilant" isn't good enough anymore.

Keep safe out there.

CyberSecurityStandardBankDataBreachSouthAfricaPOPIASupplyChainAttackInfoSec

Originally on LinkedIn

newer De-Googling my life — local-first philosophyolder Autonomous job agent (envoy) — full pipeline build