Ransomware victim disclosure
← All victimsMajor International Bank / Regulator
Claimed by Xpl0Itrs · listed 2 hours ago
Status timeline
- ListedAug 25, 2026
Current state: Listed for ransom
At a glance
- Group
- Xpl0Itrs
- Status
- Listed for ransom
- Sector
- Banking / Finance
- Listed on leak site
- Aug 25, 2026
About the victim
AI dossier — public-source company profileThe victim_name refers to a 'Major International Bank / Regulator' but the leak post describes multiple distinct victims across different sectors (banking/finance, biotech, pharmaceuticals, rail-freight logistics), not a single entity. The post appears to be a multi-victim listing rather than a focused disclosure on one target.
Attack summary
Severity: high — Multiple victims across critical sectors (banking/finance regulator, biotech, pharmaceuticals, railway logistics) with confirmed administrative system access claimed. Regulated data (financial transactions at scale, medical/pharmaceutical records) at stake across victims, though no specific exfiltration proof is published in the excerpt.The group claims to have compromised multiple organizations and obtained administrative (root) access to content management systems across several victims. The post advertises access credentials and data but provides no specific detail on what data was exfiltrated, encrypted, or the scope of the breach for each target.
Data the group says was taken
AI dossier — extracted from the leak post- CMS instances with root access
- User account credentials
- Transaction records (banking victim)
- Medical/pharmaceutical records (biotech & pharma victims)
- Logistics data (rail-freight victim)
What the group claims
Major player for the country's international banking and investment relations, main regulator and wealth management side too.
The leak post
captured from the group's site1 new sale: . Contact us to purchase. | | | | [ ](http://2kieaq6jnwgrru62wwtxaafg35q6rzweg7y2xjfnbhvq5wd4eojqv6yd.onion/company/spaggiari/) | | | [ ](http://2kieaq6jnwgrru62wwtxaafg35q6rzweg7y2xjfnbhvq5wd4eojqv6yd.onion/company/ozhairandbeauty/) | | [ ](http://2kieaq6jnwgrru62wwtxaafg35q6rzweg7y2xjfnbhvq5wd4eojqv6yd.onion/company/bmw/) | | Major international business hub, they allow commodity trading and handle company formation, commercial sales, licensing, etc. Facilitated 381 billion USD in transactions, could certainly be leveraged | | --- | | Major player for the country's international banking and investment relations, main regulator and wealth management side too | | Global biotech leader driving antibody-based therapeutics through a proprietary rapid-discovery platform and genetics programme. 4 CMS instances with root: access to records, ability to add users, files, etc | | Integrated pharmaceutical powerhouse delivering a broad portfolio of vaccines, specialty medicines and oncology drugs, operating a full-stack from R&D through manufacturing to worldwide commercial distribution across 150+ markets. 10 CMS instances across 10 countrie…
Screenshot of the leak post

Sources
Source
Indexed 2 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

