Ransomware victim disclosure
← All victimsGold Star Mortgage Financial Group, Corporation
listed as goldstarfinancial.com · Claimed by BrainCipher · listed 4 hours ago
Status timeline
- ListedSep 23, 2026
- Data leakeddate unknown
At a glance
- Group
- BrainCipher
- Status
- Data leaked
- Country
- United States
- Sector
- Financial Services
- Listed on leak site
- Sep 23, 2026
About the victim
AI dossier — public-source company profileGold Star Mortgage is a nationwide mortgage lender licensed in 47 states, founded in 2000, offering conventional, FHA, VA, USDA, jumbo, and specialty loan products. The company serves residential borrowers across multiple homeownership scenarios with over 25 years of operational history and has funded $100B+ in loans.
- Industry
- Mortgage Lending & Financial Services
- Founded
- 2000
Attack summary
Severity: critical — Confirmed exfiltration of regulated financial and personally identifiable information at significant scale: credit reports, tax documents, SSNs, and income documents from 10,300+ individuals. This constitutes regulated data (credit information and PII) material to financial services compliance and consumer harm risk.BrainCipher claims to have exfiltrated approximately 10,300 documents totaling over 10.5 GB from Gold Star Mortgage. The leaked data includes lead sheets, credit reports, tax documents, income documents, documents containing Social Security Numbers (SSNs), working materials, and agent contact information.
Data the group says was taken
AI dossier — extracted from the leak post- Lead sheets
- Credit reports
- Tax documents
- Income documents
- Social Security Numbers (SSNs)
- Agent contact information
- Working materials
Original description
AI-summarised, not from the leak postN/A I don't have reliable, verified information about a specific company operating at "goldstarfinancial.com." There are multiple businesses that have used similar "Gold Star Financial" naming conventions in different jurisdictions (this is a fairly generic name used by mortgage brokers, lending companies, and financial services firms in various countries), so I cannot confidently confirm which specific entity this domain refers to, its current operational status, ownership, or verified business details without risking inaccurate attribution. If you can provide additional context (such as the specific country, registration details, or services advertised on the site), I can help assess it more accurately. Alternatively, if this is for threat intelligence purposes, I'd recommend verifying details through domain registration records (WHOIS), business registries, or regulatory filings relevant to
The leak post
captured from the group's siteWe have approximately 10,300 (10.3k) documents from this company, with a total size of over 10.5 GB. Contents: Lead Sheets; Credit Reports; Tax Documents; Income Documents; Documents Containing SSNs; Working Materials; Agent Contacts. Leak happened on: 09.17.26. If you think you are here by mistake, please contact us at [email protected] ⏳ Deadline: September 29, 2026 at 05:33
Sources
Source
Indexed 4 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

