79 Victims for Financial Services in 2025


Sponsored by Hudson RockUse Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business


 Manufacturing|  Construction |  Transportation/Logistics |  Technology |  Healthcare |  Financial Services |  Public Sector |  Business Services |  Retail |  Consumer Services |  Energy |  Telecommunication |  Agriculture and Food Production |  Hospitality and Tourism


This page lists all the victims of ransomware attacks in Ransomware.live database for Financial Services in 2025. We continously scrape ransomware group site to detect new victims.
Ransomware.live uses AI to identify the activity of victims, but please note that the results may not be 100% accurate—do not hesitate to contact us if you notice any errors.
US flag

Andrew Davidson & Co., Inc. 

Company logo
Ransomware Group:

Discovery Date: 2025-03-24 19:24
Estimated Attack Date: 2025-02-28

Financial Services Andrew Davidson & Co., Inc. is a leading provider of risk analytics and consulting to the mortgage-backed securities (MBS) and asset-backed securities (ABS) industry. Our team was successful in extracting the following documents: Contact details of customers and employees Financial statements of the company Insurance certificates

Victim:   |  Group: 
US flag

Bunting Capital Management Inc 

Company logo
Ransomware Group:

Discovery Date: 2025-03-24 19:24
Estimated Attack Date: 2025-02-28

Finance Bunting Capital Management, located in Virginia Beach, is a team of financial advisors at Wealthway Financial Advisors who specialize in helping clients determine if they have enough resources and feel secure in their investment choices. Our team was successful in extracting the following documents: Corporate internal documents and agreements Employees medical documents Financial statements of the company Contact details of customers and employees

Group: 
US flag

Maine Highlands Federal Credit Union 

Company logo
Ransomware Group:

Discovery Date: 2025-03-24 19:24
Estimated Attack Date: 2025-03-03

Banking CUSO Mortgage Corporation - CUSO Mortgage Corp. is a licensed mortgage company owned by Maine credit unions. Our team was successful in extracting the following documents: Financial statements of the company Employees medical insurance documents Corporate internal documents and agreements

Victim:   |  Group: 
US flag

Red Credit solution, LLC 

Company logo
Ransomware Group:

Discovery Date: 2025-03-24 19:24
Estimated Attack Date: 2025-03-03

Business Services Red Credit Solutions is a debt collection and purchasing agency located in Bellevue Nebraska, servicing Iowa and Nebraska. Our team was successful in extracting the following documents: Employee and clients social security numbers Driving licenses Financial statements of the company Customer credit documents Contact information of clients and employees Corporate internal documents and agreements

Victim:   |  Group: 
 flag

Precision Accounting Intl 

Company logo
Ransomware Group:

Discovery Date: 2025-03-23 17:00

N/A

Victim:   |  Group: 
CA flag

www.gestionquintessence.com 

Company logo
Ransomware Group:

Discovery Date: 2025-03-21 19:04

[AI generated] Gestion Quintessence is a financial management company based in Quebec, Canada. It ensures optimal management of your family, personal, and business wealth. They provide services such as financial planning, tax planning, investment strategies, risk management, etc. Their professionals are dedicated to offering comprehensive support for various financial needs.

Victim:   |  Group: 
US flag

www.accessfinanceonline.com 

Company logo
Ransomware Group:

Discovery Date: 2025-03-21 18:59
Estimated Attack Date: 2025-02-28

[AI generated] N/A

Victim:   |  Group: 
KY flag

Cayman National Bank 

Company logo
Ransomware Group:

Discovery Date: 2025-03-21 15:45

N/A

Victim:   |  Group: 
PK flag

Standard Capital Securities (Pvt) Backoffice - Pakistan Stock Market Data Vault 

Company logo
Ransomware Group:

Discovery Date: 2025-03-21 01:22

Standard Capital Securities (Pvt) Backoffice - Pakistan Stock Market Data Vault

Victim:   |  Group: 
UK flag

www.georgehay.co.uk 

Company logo
Ransomware Group:

Discovery Date: 2025-03-20 18:48
Estimated Attack Date: 2025-02-26

[AI generated] George Hay Chartered Accountants is a UK-based financial company providing comprehensive financial services including auditing, accounting, corporate taxation, and business consultancy. They cater to a mix of local, national and international clients across various sectors from multiple office locations in Biggleswade, Huntingdon and Letchworth Garden City.

Victim:   |  Group: 
lk flag

Cargills Bank 

Company logo
Ransomware Group:

Discovery Date: 2025-03-20 12:27

Exfiltraded data : yes - Encrypted data : no

Victim:   |  Group: 
TW flag

Wilson Re Limited 

Company logo
Ransomware Group:

Discovery Date: 2025-03-16 07:57
Estimated Attack Date: 2025-03-12

Wilson Re (Taiwan) Limited (Taiwan)

Victim:   |  Group: 
GB flag

mdm-insurance.com 

Company logo
Ransomware Group:

Discovery Date: 2025-03-14 09:14

MDM Insurance Services Inc. offers a wide range of insurance products and services, including auto, home, and life insurance.

Victim:   |  Group: 
MC flag

Ascoma Group 

Company logo
Ransomware Group:

Discovery Date: 2025-03-13 00:49
Estimated Attack Date: 2025-03-12

ASCOMA has two cross-functional divisions: ASCOMA International, a coordination center for international operations, and ASCOMA He alth/PACTILIS, the Group’s competence center for health insurance and healthcare cost management, and more broadly for personal in surance. We are ready to upload more than 12 GB of essential corporate doc uments such as: contact numbers and e-mail addresses of employees and customers, internal correspondences, passports and other emp loyee and customer documents, etc

Victim:   |  Group: 
IN flag

hitekgroup.in india Finance 

Company logo
Ransomware Group:

Discovery Date: 2025-03-12 14:23

hitekgroup.in india Finance

Victim:   |  Group: 
US flag

Indastrial Acceptance Corporation 

Company logo
Ransomware Group:

Discovery Date: 2025-03-12 14:18

IAC offers consumer financing to both the Retail and Direct Sales market. We are ready to upload more than 60 GB of essential corporate doc uments such as: financial data (audits, payment details, reports) , health condition certificates, inside correspondences, etc.

Victim:   |  Group: 
US flag

Skyward Specialty Insurance 

Company logo
Ransomware Group:

Discovery Date: 2025-03-11 22:03

N/A

Victim:   |  Group: 
CN flag

bank.pingan.com (CN) 

Company logo
Ransomware Group:

Discovery Date: 2025-03-10 22:22

bank.pingan.com

Victim:   |  Group: 
FR flag

mazars.fr 

Company logo
Ransomware Group:

Discovery Date: 2025-03-10 11:28
Estimated Attack Date: 2023-05-22

mazars.fr company

Victim:   |  Group: 
NZ flag

Vercoe Insurance Brokers 

Company logo
Ransomware Group:

Discovery Date: 2025-03-09 20:26
Estimated Attack Date: 2025-03-05

Vercoe Insurance Brokers have been the preferred insurance brokers for Calley Building since 2008. They came to us highly recommended by family members who had a long standing relationship with the company over many years. It is the opinion of many people that dealing with insurance is stressful and time consuming, this is true if you do not have an astute company like Vercoes at the helm. We have found Linda, Adrienne and the rest of the Vercoes team to be extremely helpful and vigilant towards our business and personal insurance requirements. They have certainly lived up to the expectations we had of them and they have contributed immensely towards our strong business structures since 2008. We have full confidence in the policies Vercoe Insurance Brokers provide us as we have had to make several claims over the years and every time our policies have provided the required cover. The claim process is always stress free and managed very well by the Vercoes professional team.

Victim:   |  Group: 
US flag

Carruth Compliance Consulting 

Company logo
Ransomware Group:

Discovery Date: 2025-03-06 01:22
Estimated Attack Date: 2024-12-24

[AI generated] Carruth Compliance Consulting is a company dedicated to consulting on compliance challenges related to Tax-Advantaged Benefit Program administration. It specializes in the administration of 403(b) and 457(b) retirement plans. The company helps employers and financial institutions navigate complex tax laws and compliance regulations relating to benefit plans, providing compliance consulting, plan administration, and ongoing compliance support.

Victim:   |  Group: 
US flag

Best Collateral, Inc. 

Company logo
Ransomware Group:

Discovery Date: 2025-03-05 10:12

Best Collateral, Inc. Headquartered in San Rafael, California, Best Collateral opened its first store in 1903 in San Francisco and provides financial services to individuals, families and small businesses.

Group: 
US flag

Lakeshore Title Agency 

Company logo
Ransomware Group:

Discovery Date: 2025-03-04 20:27
Estimated Attack Date: 2025-01-31

Lakeshore Title Agency has closed over $100 million in commercial transactions and over $700 million in residential refinances and purchases. Leak size: 341GB.

Victim:   |  Group: 
GB flag

Makesworth Accountants 

Company logo
Ransomware Group:

Discovery Date: 2025-03-04 20:26
Estimated Attack Date: 2025-02-09

Makesworth Accountants is multi-award-winning accountancy practice of a chartered accountant, tax and business advisers. Leak size: 176.4GB.

Victim:   |  Group: 
ZA flag

LINKGROUP 

Company logo
Ransomware Group:

Discovery Date: 2025-03-03 20:02

Hard landscaping including new patios, retaining walls, rockeries, decking,…

Victim:   |  Group: 
US flag

Couri Insurance Agency 

Company logo
Ransomware Group:

Discovery Date: 2025-03-02 20:05

United States

Victim:   |  Group: 
US flag

Donna G. Rogers, CPA, P.A. 

Company logo
Ransomware Group:

Discovery Date: 2025-02-27 14:37

Focusing on customer service, we provide accounting solutions for small to mid-sized businesses with the use of QuickBooks software.

Victim:   |  Group: 
US flag

F&V Capital Management, LLC (FVCM) 

Company logo
Ransomware Group:

Discovery Date: 2025-02-27 14:34

F&V Capital Management, LLC (FVCM) is an SEC registered investment advisor that offers customized asset management solutions using U.S. and European traded equities, fixed income and other short-term and liquid securities for a wide variety of international clients.

Victim:   |  Group: 
US flag

Muller Insurance 

Company logo
Ransomware Group:

Discovery Date: 2025-02-26 21:07

United States

Victim:   |  Group: 
GB flag

London Belgravia 

Company logo
Ransomware Group:

Discovery Date: 2025-02-25 22:54
Estimated Attack Date: 2025-02-19

London Belgravia Brokers provide risk insurance and finance advisory solutions to global property developers, investors and high net worth individuals.

Victim:   |  Group: 
US flag

First Federal Savings & Loan 

Company logo
Ransomware Group:

Discovery Date: 2025-02-25 22:33

United States

Victim:   |  Group: 
MT flag

Merkanti Bank Ltd 

Company logo
Ransomware Group:

Discovery Date: 2025-02-25 16:09

Merkanti Bank Ltd (formerly MFC Merchant Bank Ltd) is a credit in stitution licensed by the Malta Financial Services Authority (Reg istration No: C31608) and is focused primarily on merchant bankin g services, factoring and general corporate banking services. We are ready to upload a lot of essential corporate documents suc h as: financial data (audits, payment details, reports) and many internal databases.

Group: 
GE flag

South Georgia Accounting Services 

Company logo
Ransomware Group:

Discovery Date: 2025-02-25 14:43
Estimated Attack Date: 2025-02-23

South Georgia Accounting ServicesProviding Accounting and Tax services that you can count on.Enrolled Agent authorized by the IRS . Specializing in all aspects of small business accounting.- Database with company accounting- Quickbooks Client Files https://sgaccountingservices.com/

Victim:   |  Group: 
US flag

pacresmortgage.com 

Company logo
Ransomware Group:

Discovery Date: 2025-02-25 01:56

The PacRes story of growth continues to this day because our employees give everything to make their work valuable to others’ lives.

Victim:   |  Group: 
US flag

associatedasset.com 

Company logo
Ransomware Group:

Discovery Date: 2025-02-24 12:02
Estimated Attack Date: 2025-02-06

Business Services. “Founded in 1990, AAM has become a trusted household name in community management. So, what sets AAM apart as the premier partner to over 1,000 community associations nationwide? It’s simple. We love what we do and are flexible, adaptable, and willing to work with our Boards to build a detailed support system.” Website: https://www.associatedasset.com/ Revenue : $288M Address: 1600 W Broadway Rd Ste 200, Tempe, Arizona, 85282, United States Phone Number: (602) 957-9191 Download link #1: https://[redacted].onion/ASSOCIATEDASSET/PROOF/ Mirror: https://[redacted].onion/ASSOCIATEDASSET/PROOF/ DATA DESCRIPTIONS: Personal identifiable information, executives personal docs, corporate OneDrive, financial data, corp correspondence, agreements\NDAs\contracts, etc.

Victim:   |  Group: 
CA flag

www.witheyaddison.com 

Company logo
Ransomware Group:

Discovery Date: 2025-02-21 21:06
Estimated Attack Date: 2025-02-15

[AI generated] Withey Addison LLP, often mentioned as www.witheyaddison.com, is a professional service accounting firm based in Ontario, Canada. It offers a variety of finance and accounting services including corporate taxation, business advisory services, financial planning and more. The firm is committed to providing superior service to clients in various industries.

Victim:   |  Group: 
US flag

Luminus Management 

Company logo
Ransomware Group:

Discovery Date: 2025-02-21 16:37
Estimated Attack Date: 2025-02-04

Luminus Management is an investment management firm founded in 20 02 with offices in New York, NY and Houston, TX. The firm focuses on a low net, long/short, relative value oriented strategy that invests opportunistically across the capital structure of compani es. We are ready to upload a lot of essentials corporate documents su ch as: NDA’s, driver licenses, passports, financial data (audits, payment details, reports), employee medical documents, etc.

Victim:   |  Group: 
CA flag

BeniPlus 

Company logo
Ransomware Group:

Discovery Date: 2025-02-19 06:03

N/A

Victim:   |  Group: 
US flag

myhscu.com 

Company logo
Ransomware Group:

Discovery Date: 2025-02-17 22:22
Estimated Attack Date: 2025-02-14

Heritage South Credit Union was originally chartered in 1937 as the Avondale Employees Federal Credit Union. After many years and a couple of name changes, Heritage South Credit Union continues to have a strong presence in Sylacauga, Childersburg, Moody, and Alexander City as a fixture in the community and as a stable and secure financial institution. Heritage South Credit Union has grown to over $160 million in assets and over 14,000+ members. - 300 GB data including: - debit card numbers - account numbers - SSN - address - phone - email - DOB - current balances - debts - loans - insurance Here's data for CEO: JAMIE MCCAA PAYTON 3993 ODENS MILL RD SYLACAUGA AL 35151 DOB: 1969-11-18 SSN: 423-04-5662 Phone: 256-872-2885|256-245-0777 Email: jpayton@myhscu.com|cedarcreekcowboychurch@yahoo.com|jamie.hscu@gmail.com SPOUSE: CHRIS PAYTON (416-82-5751 1967-12-01)

Victim:   |  Group: 
 flag

DA Capital 

Company logo
Ransomware Group:

Discovery Date: 2025-02-17 11:44

DA Capital LLC is a global investment manager specializing in cre dit and special situations. We are ready to upload a lot of sensitive corporate documents suc h as: NDA’s, employee credit cards, confidential licenses, agreem ents and contracts, employee medical cards, insurance documents, passports and visas, tax information, driver licenses, contact nu mbers and e-mail addresses of employees and customers, etc.

Group: 
US flag

Heritage South Credit Union 

Company logo
Ransomware Group:

Discovery Date: 2025-02-14 18:02

Heritage South Credit Union was originally chartered in 1937 as the Avondale Employees Federal Credit Union. After many years and a couple of name changes, Heritage South Credit Union continues to have a strong presence in Sylacauga, Childersburg, Moody, and Alexander City as a fixture in the community and as a stable and secure financial institution. Heritage South Credit Union has grown to over $160 million in assets and over 14,000+ members. - 300 GB data including: - debit card numbers - account numbers - SSN - address - phone - email - DOB - current balances - debts - loans - insurance Here's data for CEO: ...

Victim:   |  Group: 
US flag

Nelson & Townsend, CPA's 

Company logo
Ransomware Group:

Discovery Date: 2025-02-14 15:49

Nelson & Townsend, CPA's perform tax returns for individuals and businesses, accounting services (payroll services, bookkeeping), and business/client support. We are ready to upload a lot of essentials corporate documents su ch as: driver licenses, financial data (audits, payment details, reports), contact numbers and e-mail addresses of employees and c ustomers, etc.

Group: 
US flag

Financial Services of America, Inc. 

Company logo
Ransomware Group:

Discovery Date: 2025-02-13 14:16

Financial Services of America (also known as FSA) is one of the largest independent financial planning and insurance firms in Michigan.

Victim:   |  Group: 
US flag

Layfield & Borel CPA's L.L.C 

Company logo
Ransomware Group:

Discovery Date: 2025-02-13 14:14

Layfield & Borel CPA's L.L.C. is a verified accounting firm, offering accounting and tax preparation services to customers and small business owners located in and around Baton Rouge, Louisiana.

Victim:   |  Group: 
US flag

Dan Eckman CPA 

Company logo
Ransomware Group:

Discovery Date: 2025-02-13 13:28

an Eckman CPA offer personal tax services along with a suite of small business accounting solutions that inclu des bookkeeping, tax planning and preparation, and fina ncial reporting. You will find more than 10 GB of private corporate docu ments such as: financial data (audits, payment details, reports), contact numbers and e-mail addresses of empl oyees and customers, internal confidential agreements a nd contracts, inside corporate correspondence, etc. We have made the process of downloading company data as simple as possible for our users. All you need is any torrent client (like Vuze, Utorrent, qBittorrent or Tra nsmission to use magnet links). You will find the torre nt file above. 1. Open uTorrent, or any another torrent client. 2. Add torrent file or paste the magnet URL to upload t he data safely. 3. Archives have no password. MAGNET URL: magnet:?xt=urn:btih:884A5E0AFDF5F0ED8193DA7 B2CD439A9F5852331&dn=eckmancpa.com&tr=udp://tracker.ope nbittorrent.com:80/announce&tr=udp://tracker.opentrackr .org:1337/announce

Group: 
US flag

laderalending.com 

Company logo
Ransomware Group:

Discovery Date: 2025-02-12 14:41

[AI generated] Ladera Lending is a full-service mortgage banking firm based in the United States. They specialize in providing a wide range of loan services, including purchase loans, refinance, home equity loans and reverse mortgages. The company aims to cater to individuals' unique needs with customized, flexible solutions. Their seasoned professionals offer comprehensive financial advice and guide customers throughout the loan process.

Victim:   |  Group: 
US flag

Wakefield & Associates 

Company logo
Ransomware Group:

Discovery Date: 2025-02-11 13:26
Estimated Attack Date: 2023-11-30

Wakefield & Associates is a financial services company that speci alizes in debt collection and billing services. We are ready to upload more than 13 GB of sensitive private corpo rate documents such as: SSNs, passport numbers, confidential lice nses, agreements and contracts, financial data (audits, payment d etails, reports), contact numbers and e-mail addresses of employe es and customers, medical insurance documents, internal correspon dences, medicare numbers, etc.

Wakefield & Associates has been previously claimed by Knight for an attack estimated on 2023-11-30.

This could suggest a new attack, a cross-claim between brands by the same threat actor, or the recycling of previously leaked stolen data.

Update Date: 2025-02-11

Group: 
US flag

Prime Trust Financial 

Company logo
Ransomware Group:

Discovery Date: 2025-02-11 13:26

Prime Trust Financial offers a range of financial services includ ing bill payment, cambio, financing, gift cards, and send/receive money. Their services cater to individuals looking to pay bills, shop gift cards, exchange currency, and obtain micro-financing l oans. We are ready to upload more than 68 GB of sensitive corporate doc uments such as: driver licenses, passports, contact numbers and e -mail addresses of employees and customers, financial data (audit s, payment details, reports), confidential licenses, agreements a nd contracts, etc.

Group: 
PH flag

abcapital.com.ph 

Company logo
Ransomware Group:

Discovery Date: 2025-02-10 16:47

sourcecode and database zip itd_1002

Victim:   |  Group: 
GB flag

Adler Shine LLP 

Company logo
Ransomware Group:

Discovery Date: 2025-02-10 16:01
Estimated Attack Date: 2025-02-07

Adler Shine LLP (founded in 1986) - the company provides the processing of AIM & ISDX market transactions, an outsort for business processes, tax management services, the organization of mass events with the participation of famous personalities. Adler Shine LLP corporate office is located in Aston House, Cornwall Avenue, London N3 1LF LLP No. OC301724, UK. The total amount of data leakage is 332.20 GB

Victim:   |  Group: 
 flag

Capital Cell Global (CCG) 

Company logo
Ransomware Group:

Discovery Date: 2025-02-10 15:31

N/A

Victim:   |  Group: 
 flag

BERKSHIREINC.COM 

Company logo
Ransomware Group:

Discovery Date: 2025-02-10 15:06

[AI generated] BerkshireInc.com is a website associated with Berkshire Hathaway Inc., a multinational conglomerate headed by Warren Buffett. The website allows users to access comprehensive information about Berkshire Hathaway's numerous subsidiary businesses, annual reports, and letters to shareholders. It also provides updates on stock price, earnings, and more. The company engages in diverse industry sectors including investments, insurance, utilities, and manufacturing.

Victim:   |  Group: 
CA flag

renmarkfinancial.com 

Company logo
Ransomware Group:

Discovery Date: 2025-02-07 10:24
Estimated Attack Date: 2025-02-05

All data of this company will be available for download on 17.02.2025.Renmark Financial Communications Inc. is a full service investor relations firm representing small, medium and large cap public companies trading on all major North America ...

Victim:   |  Group: 
AU flag

Hall Chadwick 

Company logo
Ransomware Group:

Discovery Date: 2025-02-05 20:41

Hall Chadwick, headquartered in Sydney, New South Wales, is an accounting firm. Their services include audit and assurance, corporate finance, financial planning, taxation, insolvency and business recovery, and forensic accounting.

Victim:   |  Group: 
US flag

dwgp.com 

Company logo
Ransomware Group:

Discovery Date: 2025-02-04 17:42

Extract from Taking stock of 2024 Part 2

Victim:   |  Group: 
CA flag

capstoneins.ca 

Company logo
Ransomware Group:

Discovery Date: 2025-02-04 15:47

[AI generated] Capstone Insurance Brokers Ltd, based in Canada, provides wide-ranging insurance services covering personal, business, and life and health insurance. They aim to offer unmatched professional service, guaranteeing customers top-rate policies. With their expertise, Capstone ensures personalized solutions that cater to individual and business needs with maximum value and protection. Their team is dedicated with a commitment to delivering superior customer service.

Victim:   |  Group: 
US flag

gaheritagefcu.org 

Company logo
Ransomware Group:

Discovery Date: 2025-02-04 06:21

[AI generated] Georgia Heritage Federal Credit Union, often abbreviated as GA Heritage FCU, is a community-based financial institution in the United States. Founded in 1940, it offers a variety of financial services to its members. These include checking and savings accounts, credit cards, business services, home and auto loans, and financial education. Known for its focus on community involvement, it maintains a commitment to provide top-quality financial services in a friendly and professional manner.

Victim:   |  Group: 
US flag

DRI Title & Escrow 

Company logo
Ransomware Group:

Discovery Date: 2025-02-03 12:15

DRI Title & Escrow was founded in 2001 and is headquartered in Omaha, Nebraska. DRI Title & Escrow is a technology driven real estate information and transactional management company that provides title insurance and settlement services in si ...

Victim:   |  Group: 
CA flag

realtaxcanada.com 

Company logo
Ransomware Group:

Discovery Date: 2025-02-03 09:59
Estimated Attack Date: 2025-01-17

Accounting Services · Canada | clients' data. 5 GB

realtaxcanada.com has been previously claimed by Kairos for an attack estimated on 2025-01-17.

This could suggest a new attack, a cross-claim between brands by the same threat actor, or the recycling of previously leaked stolen data.

Update Date: 2025-02-03

Victim:   |  Group: 
US flag

rqsi.com 

Company logo
Ransomware Group:

Discovery Date: 2025-01-31 15:17

Extract from Taking stock of 2024 Part 1

Victim:   |  Group: 
US flag

sgbllp.com 

Company logo
Ransomware Group:

Discovery Date: 2025-01-31 15:13

Extract from Taking stock of 2024 Part 1

Victim:   |  Group: 
 flag

Premierautocredit.com 

Company logo
Ransomware Group:

Discovery Date: 2025-01-29 19:28

Country: USA Views: 53 View more /pac Public 156GB

Victim:   |  Group: 
IN flag

dealplexus.com 

Company logo
Ransomware Group:

Discovery Date: 2025-01-27 07:46

dealplexus.com

dealplexus.com has been previously claimed by Funksec for an attack estimated on 2024-12-11.

This could suggest a new attack, a cross-claim between brands by the same threat actor, or the recycling of previously leaked stolen data.

Update Date: 2025-01-27

Victim:   |  Group: 
US flag

bee-insurance.com 

Company logo
Ransomware Group:

Discovery Date: 2025-01-27 07:45

bee-insurance.com

bee-insurance.com has been previously claimed by Funksec for an attack estimated on 2024-12-13.

This could suggest a new attack, a cross-claim between brands by the same threat actor, or the recycling of previously leaked stolen data.

Update Date: 2025-01-27

Victim:   |  Group: 
CO flag

lamundialdeseguros.com 

Company logo
Ransomware Group:

Discovery Date: 2025-01-27 07:44

lamundialdeseguros.com

lamundialdeseguros.com has been previously claimed by Funksec for an attack estimated on 2024-12-13.

This could suggest a new attack, a cross-claim between brands by the same threat actor, or the recycling of previously leaked stolen data.

Update Date: 2025-01-27

Victim:   |  Group: 
ID flag

www.merchant.id 

Company logo
Ransomware Group:

Discovery Date: 2025-01-27 07:28

www.merchant.id

www.merchant.id has been previously claimed by Ransomhub for an attack estimated on 2024-03-06.

This could suggest a new attack, a cross-claim between brands by the same threat actor, or the recycling of previously leaked stolen data.

Update Date: 2025-01-27

Victim:   |  Group: 
US flag

www.betteraccountingsolutions.com 

Company logo
Ransomware Group:

Discovery Date: 2025-01-27 07:20

www.betteraccountingsolutions.com

www.betteraccountingsolutions.com has been previously claimed by Ransomhub for an attack estimated on 2024-04-06.

This could suggest a new attack, a cross-claim between brands by the same threat actor, or the recycling of previously leaked stolen data.

Update Date: 2025-01-27

Victim:   |  Group: 
IN flag

Let’s Secure Insurance 

Company logo
Ransomware Group:

Discovery Date: 2025-01-26 14:23

N/A

Victim:   |  Group: 
IN flag

genrepurchase.bankatm.in 

Company logo
Ransomware Group:

Discovery Date: 2025-01-24 22:43

[AI generated] "genrepurchase.bankatm.in" is a company that appears to be involved in the banking and financial industry, specifically in ATM operations. Their name suggests that they might be facilitating or managing ATM sales or purchases, perhaps offering comprehensive solutions for banks and financial institutions. However, not much info is publicly available without their relevant sources.

Victim:   |  Group: 
US flag

EMKAY.COM 

Company logo
Ransomware Group:

Discovery Date: 2025-01-24 17:21

[AI generated] EMKAY Inc. is a business service provider specializing in fleet leasing and management solutions. Founded in 1946, EMKAY operates across North America and caters to a wide range of industry sectors. Offering services like lease financing, fuel management, accident management, licensing compliance, and more, EMKAY aims to help businesses manage their vehicle fleets efficiently and cost-effectively.

Victim:   |  Group: 
US flag

CLEO.COM 

Company logo
Ransomware Group:

Discovery Date: 2025-01-24 08:18

[AI generated] CLEO.COM is a fintech startup that offers an AI-driven budget assistant to help individuals manage their finances. Its primary service enables budgeting, saving, and tracking spendings in an innovative way. Geared towards millennials, Cleo provides insights into spending habits, gives financial advice, and allows for easy management of money across multiple accounts. It operates in the UK and the US.

Victim:   |  Group: 
US flag

WESTERNALLIANCEBANK.COM 

Company logo
Ransomware Group:

Discovery Date: 2025-01-24 08:16

[AI generated] Western Alliance Bancorporation is a leading bank holding company in the US offering retail, commercial, and real estate banking services. Established in 1995, it operates through various divisions and subsidiaries across the nation. Western Alliance Bank provides lending, deposit, treasury management, and online banking solutions to consumers, small to larger businesses, and professional communities.

Victim:   |  Group: 
AT flag

Bwfg.at 

Company logo
Ransomware Group:

Discovery Date: 2025-01-23 18:39

Bwfg.at Country: austria Views: 16 View more /bwfg Public 102GB

Victim:   |  Group: 
US flag

www.missionbank.bank 

Company logo
Ransomware Group:

Discovery Date: 2025-01-23 09:38

[AI generated] Mission Bank is a full-service, community-based bank based in California. They offer an array of products and services like personal banking, commercial banking, wealth management and online banking. Their goal is to foster community growth by providing personalized financial solutions to local businesses and individuals.

Victim:   |  Group: 
US flag

boardman-hamilton.com 

Company logo
Ransomware Group:

Discovery Date: 2025-01-21 22:58

[AI generated] Boardman-Hamilton Company is a full-service, independent insurance agency. Located in Philadelphia, they have been in business for over 80 years. They provide a comprehensive range of insurance services, including personal, business, health, life, and special risk insurance. They offer personalized service, focusing on understanding individual client needs, ensuring adequate coverage at cost-effective rates. They have a skilled team of insurance professionals who guide clients in making informed insurance decisions.

Victim:   |  Group: 
IN flag

icicibank.com 

Company logo
Ransomware Group:

Discovery Date: 2025-01-21 16:26

Banking · India

Victim:   |  Group: 
IN flag

FAAB Invest Advisors Private Limited 

Company logo
Ransomware Group:

Discovery Date: 2025-01-21 14:53

N/A

Victim:   |  Group: 
US flag

thecitybank.com 

Company logo
Ransomware Group:

Discovery Date: 2025-01-21 14:43

[AI generated] City Bank is one of the oldest private Commercial Banks operating in Bangladesh. It offers different types of banking services like retail banking, SME, credit cards, treasury, and corporate banking. The bank shows remarkable growth through the adoption of modern technology, efficient customer service, and a variety of banking products. It's committed to satisfy stakeholders and contribute to the country's economy.

Victim:   |  Group: 
GB flag

compass-underwriting-ltd 

Company logo
Ransomware Group:

Discovery Date: 2025-01-20 13:59

compass-underwriting-ltd Our History Originally a Lloyd’s syndicate, Compass has evolved since 1986 to become one of the UK’s leading Accident & Health underwriting agencies and was acquired by the elseco group in April 2022. Accessing a wide range of UK, European, and Lloyd’s markets, Compass provides a full-cycle service to its’ intermediaries and their clients. Our Mission We are dedicated in providing the services needed to help launch accident and health products into your clients’ niche sectors. Compass has a long track record of designing new and innovative products for both start-ups and major players in the UK and European markets. Our Systems Compass operates a comprehensive fulfillment system that seamlessly manages all elements of a sale transaction. From quote to premium collection, plus high-quality MI, you can benefit from our fully hosted toolkit of IT solutions. Cloud hosted, you can access the system from anywhere in the World. Our Status Compass Underwriting is a trading name of Vivet Limited which is a private limited company registered in England (No. 07632781) with a registered address at 35 Ballards Lane, London, England, N3 1XW and is authorised and regulated by the Financial Conduct Authority (FCA Register Firm No. 565079). Vivet Ltd is a member of the Managing General Agents’ Association.Geo: United Kingdom - Leak size: 135 GB Archive - Contains: Files, SQL

Victim:   |  Group: