Ransomware victim disclosure
← All victimsHungarian Investment Promotion Agency
listed as Hungarian Investment Promotion Agency Press Release · Claimed by Monti · listed 3 years ago
Status timeline
- ListedJul 22, 2023
- Data leakeddate unknown
At a glance
- Group
- Monti
- Status
- Data leaked
- Country
- Hungary
- Sector
- Financial Services
- Listed on leak site
- Jul 22, 2023
- Ransom demanded
- $5M
About the victim
AI dossier — public-source company profileThe Hungarian Investment Promotion Agency (HIPA) is a Hungarian government-affiliated agency responsible for attracting and facilitating foreign direct investment into Hungary. It operates under the authority of the Hungarian government and supports international companies seeking to establish or expand operations in Hungary. The agency employs approximately 11-20 people and operates primarily from Budapest.
- Industry
- Government Investment Promotion Agency
- Address
- Budapest, Hungary
- Employees
- 11-20
Attack summary
Severity: high — HIPA is a government-linked investment promotion body; confirmed data publication by Monti suggests exfiltration of potentially sensitive government and business data including investment plans, counterparty information, and internal records. The government/quasi-public sector nature and data publication elevate this beyond medium severity.The Monti ransomware group claims to have attacked HIPA and has published data ('data_published' status), demanding a $5M ransom. The post implies exfiltration of company data, though specific data categories and volume are not detailed in the leak post.
Data the group says was taken
AI dossier — extracted from the leak post- Internal business documents
- Employee records
- Financial data
- Investment-related correspondence
What the group claims
Hungarian Investment Promotion Agency is a company that operates in the Financial Services industry. It employs 11-20 people and has $5M-$10M of revenue.
Sources
Source
Indexed 3 years agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

