Ransomware victim disclosure
← All victimsThinkMarkets
listed as thinkmarkets.com · Claimed by chaos · listed 5 months ago
Status timeline
- Listed
Dec 8, 2025
- Data leaked
At a glance
- Group
- chaos
- Status
- Data leaked
- Country
- Australia
- Sector
- Financial Services
- Listed on leak site
- Dec 8, 2025
About the victim
AI dossier — public-source company profileThinkMarkets is a multi-asset online brokerage founded in 2010, headquartered in London and Melbourne with regional hubs across Asia-Pacific, the Middle East and North Africa, Europe, and South America. The firm offers trading in over 4,000 instruments including Forex, CFDs, commodities, indices, and cryptocurrencies via its proprietary ThinkTrader platform. It is regulated by multiple authorities including CySEC and serves retail and institutional clients globally.
- Industry
- Online CFD & Multi-Asset Brokerage
- Address
- Level 25, 525 Collins Street, Melbourne VIC 3000, Australia / 1 Canada Square, Canary Wharf, London E14 5AB, United Kingdom
- Employees
- 201-500
- Founded
- 2010
Attack summary
Severity: critical — ThinkMarkets is a regulated financial brokerage handling highly sensitive regulated data including customer PII, financial account details, and payment information at global scale; data_published status confirms exfiltration and public release of this regulated financial data.The Chaos ransomware group claims to have compromised ThinkMarkets and has published data (disclosed status: data_published), though the leak post provides no specific details on the volume or type of data exfiltrated, nor whether encryption was performed.
Data the group says was taken
AI dossier — extracted from the leak post- Customer account records
- Financial trading data
- Personal identification information
- Payment and banking details
- Internal business documents
What the group claims
Founded in 2010, ThinkMarkets is a multi-asset online brokerage with headquarters in London and Melbourne and hubs in the Asia-Pacific, the Middle East and North Africa, Europe, and South America.
Sources
Source
Indexed 5 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
