Ransomware victim disclosure
← All victimsFullerton India
Claimed by Snatch · listed 3 years ago
Status timeline
- ListedJun 13, 2023
- Data leakeddate unknown
At a glance
- Group
- Snatch
- Status
- Data leaked
- Country
- India
- Sector
- Financial Services
- Listed on leak site
- Jun 13, 2023
About the victim
AI dossier — public-source company profileFullerton India Credit Company Limited is a Reserve Bank of India-registered non-banking financial company (NBFC) headquartered in Mumbai, India. It provides a wide range of retail lending products including personal loans, home loans, vehicle loans, SME loans, and rural finance to individuals and small businesses across India. The company operates an extensive branch network spanning urban, semi-urban, and rural markets.
- Industry
- Non-Banking Financial Company (NBFC) / Consumer Lending
- Employees
- 1001-5000
- Founded
- 2007
Attack summary
Severity: critical — Fullerton India is a large NBFC handling sensitive regulated financial data (loan applications, income details, identity documents, credit information) for potentially millions of retail and SME customers in India. Confirmed data publication by the threat actor constitutes exfiltration of regulated PII and financial records at scale, meeting the critical threshold.The Snatch ransomware group claims to have exfiltrated data from Fullerton India and has published it ('data_published' status), indicating confirmed data exfiltration of financial services customer and business records. The leak post references loan-related customer financial data.
Data the group says was taken
AI dossier — extracted from the leak post- Customer loan records
- Personal financial information
- Loan eligibility data
- Customer PII
- Business financial documents
What the group claims
Fullerton India offers a range of calculators to help you make an informed decision regarding the best possible solution to serve your financials needs. Access these free of cost, to get a quick estimates of loan amount you are eligible for. You can also access
Sources
Source
Indexed 3 years agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

