Ransomware victim disclosure
← All victimsBPCE International (BPCE IOM) – Ho Chi Minh City Branch
listed as Groupe BPCE · Claimed by Thegentlemen · listed 1 day ago
Status timeline
- ListedAug 7, 2026
- Data leakeddate unknown
At a glance
- Group
- Thegentlemen
- Status
- Data leaked
- Country
- Vietnam
- Sector
- Financial Services
- Listed on leak site
- Aug 7, 2026
About the victim
AI dossier — public-source company profileBPCE International (formerly Natixis), the Ho Chi Minh City branch of France's second-largest banking group Groupe BPCE, has operated in Vietnam since 1988. It holds a full banking license and specializes in corporate and investment banking, offering specialized finance, trade solutions, and transaction processing to regional businesses.
- Industry
- Banking & Financial Services – Corporate & Investment Banking
- Address
- Ho Chi Minh City, Vietnam
- Founded
- 1988
Attack summary
Severity: high — Confirmed exfiltration claim against a regulated financial institution (banking sector) holding corporate and client financial data at scale. No proof files advertised reduces confidence slightly, but the regulated nature and data sensitivity justify 'high'.The group claims to have compromised BPCE International's Ho Chi Minh City branch and exfiltrated data. The leak post does not specify encryption, operational disruption, or detailed data categories.
Data the group says was taken
AI dossier — extracted from the leak post- Corporate banking records
- Transaction processing data
- Client financial information
- Trade finance documentation
What the group claims
bpce-vietnam.com zoominfo.com/c/groupe-bpce/457963650 BPCE International (formerly Natixis), the Ho Chi Minh City branch of France’s second-largest banking group, Groupe BPCE. Operating in Vietnam since 1988, it is one of the country's longest-established foreign bank branches, holding a full banking license. The institution specializes in corporate and investment banking, offering specialized finance, trade solutions, and transaction processing to businesses across the region.
Sources
Source
Indexed 1 day agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

