Ransomware victim disclosure
← All victimsKnight Barry Title
Claimed by Snatch · listed 3 years ago
Status timeline
- ListedSep 3, 2023
- Data leakeddate unknown
At a glance
- Group
- Snatch
- Status
- Data leaked
- Country
- United States
- Sector
- Insurance
- Listed on leak site
- Sep 3, 2023
- Data size
- 10 TB
- Records
- 500 employees
About the victim
AI dossier — public-source company profileKnight Barry Title is a title insurance and settlement services company operating across five U.S. states. The company processes over 120,000 service orders annually and maintains a customer base reportedly exceeding one million unique customers. It is one of the larger regional title insurance providers in the Midwest/United States.
- Industry
- Title Insurance & Settlement Services
- Employees
- 500+
Attack summary
Severity: critical — Confirmed exfiltration of over 10 TB of data including PII at scale (1M+ unique customer records) and financial records from a title insurance company, which routinely handles highly sensitive regulated data such as SSNs, banking details, property records, and mortgage information.The Snatch ransomware group claims to have exfiltrated over 10 TB of data from Knight Barry Title, including customer data and financial records representing approximately ten years of company history, and states the data is ready for publication.
Data the group says was taken
AI dossier — extracted from the leak post- Customer personal data (1M+ unique records)
- Financial records
- Commercial business data
- Service order records (10 years historical)
What the group claims
We are produly present over 10TB ofcommercial data (customer data, finance) for Knight Barry Title Insurance company represeting 10y data. It has over 500 employees in 5 states and executes over 120K service orders annualy which makes over 1M of unique customer data available. Ready
Sources
Source
Indexed 3 years agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

