Ransomware victim disclosure
← All victimsHungarian Investment Promotion Agency
Claimed by Monti · listed 3 years ago
Status timeline
- ListedJul 30, 2023
- Data leakeddate unknown
At a glance
- Group
- Monti
- Status
- Data leaked
- Country
- Hungary
- Sector
- Government
- Listed on leak site
- Jul 30, 2023
- Ransom demanded
- $5M
About the victim
AI dossier — public-source company profileThe Hungarian Investment Promotion Agency (HIPA) is a Hungarian government agency responsible for attracting foreign direct investment into Hungary and supporting the expansion of existing investors. It operates under the oversight of the Hungarian government and serves as the primary national body for investment facilitation and promotion. The agency works with international companies to facilitate business entry and growth within Hungary.
- Industry
- Government Investment Promotion Agency
- Employees
- 11-20
Attack summary
Severity: high — The victim is a government investment promotion agency handling sensitive foreign investment data and business intelligence; data has been published (confirmed exfiltration), which represents significant exposure of potentially sensitive government and commercial information even if the specific data categories are unconfirmed.The Monti ransomware group claims to have attacked the Hungarian Investment Promotion Agency and has published data (disclosed status: data_published), demanding a $5M ransom. The leak post implies exfiltration of company data, though specific data categories and volume are not detailed in the post.
Data the group says was taken
AI dossier — extracted from the leak post- Business/financial records
- Employee data
- Investment project documentation
- Internal communications
What the group claims
Hungarian Investment Promotion Agency is a company that operates in the Financial Services industry. It employs 11-20 people and has $5M-$10M of revenue.
Sources
Source
Indexed 3 years agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

