Ransomware victim disclosure
← All victimsArgentem Creek Partners (investment firm)
Claimed by N0n · listed 3 hours ago
Status timeline
- ListedSep 18, 2026
- Data leakeddate unknown
At a glance
- Group
- N0n
- Status
- Data leaked
- Country
- United States
- Sector
- Financial Services
- Listed on leak site
- Sep 18, 2026
About the victim
AI dossier — public-source company profileArgentem Creek Partners is an emerging markets investment specialist firm focusing on Latin America, Emerging Asia, and Eastern Europe. The firm offers special situations and structured capital solutions to investors, claiming over 250 years of cumulative team experience.
- Industry
- Investment Management & Private Credit
Attack summary
Severity: high — Confirmed exfiltration of significant business infrastructure data (complete network maps, connection records, internal systems) and tax/investor documents from a financial services firm; operational disruption claimed (network blackout).N0n claims to have exfiltrated the firm's complete corporate network evidence including 2.5M+ connection records and internal systems maps (Active Directory, SharePoint, MSP tooling, office-security integrations), along with tax-season document flows from the firm and its investor document delivery platform. The group states corporate connectivity has been severed until settlement.
Data the group says was taken
AI dossier — extracted from the leak post- 2.5M+ connection records
- Active Directory configuration
- SharePoint contents
- MSP tooling access
- Office-security integrations
- Tax-season documents
- Investor document delivery platform data
What the group claims
Investment management / private credit · United States | Full corporate network evidence: 2.5M+ connection records, complete internal systems map (Active Directory, SharePoint, MSP tooling, office-security integrations); Tax-season document flows of the firm and its investor document delivery platform | Corporate connectivity remains severed until settlement. | [ACTIVE: deadline 2026-09-21 03:01 UTC]
The leak post
captured from the group's site# Your data has a deadline. Organizations below lost control of their networks. When the countdown ends without payment, their data becomes public. Those who honored their deadline are remembered with respect. Victim representatives: use the personal key from your ransom note to reach your negotiation room. Marketing analytics SaaS / data platform · United States #### What will be published if no settlement is reached * Full multi-tenant production database: 73,254 platform users across 11,504 customer tenants, 151,311 end-client records with names, emails, phone numbers and addresses * 36,948 OAuth grants to customers' advertising accounts (Facebook Ads, Google Ads, LinkedIn, Mailchimp, Shopify and others) across 5,515 tenants * Production database archive manifest: 4 TB of per-tenant database archives including LoanDepot, Toptal, Scripps, Advance Digital, Wpromote, Greystar, Cumulus Media and thousands more Their 5,000+ customers will be notified directly. Education / Labor Union · US — New York #### What will be published if no settlement is reached * The union’s complete legal case archive — approx. 181,420 documents: grievance and arbitration files, disciplinary appe…
Sources
Source
Indexed 3 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

