Ransomware victim disclosure
← All victimslopay
Claimed by Black X · listed 5 hours ago
Status timeline
- ListedOct 9, 2026
- Data leakeddate unknown
At a glance
- Group
- Black X
- Status
- Data leaked
- Country
- United Kingdom
- Sector
- Financial Services
- Listed on leak site
- Oct 9, 2026
About the victim
AI dossier — public-source company profileLopay is a UK-based fintech company providing a payment platform for SMEs and sole traders. They offer point-of-sale systems, card readers, mobile payment acceptance, and an integrated expense and rewards card, positioning themselves as a low-cost alternative to competitors like SumUp and Zettle.
- Industry
- Financial Services / Fintech - Payment Processing
Attack summary
Severity: critical — Confirmed exfiltration of regulated financial data at scale (payment card details, banking data, transaction records) affecting multiple client companies. Data involves PII and sensitive financial information subject to regulatory requirements (PCI-DSS, UK Financial Conduct Authority).Black X claims to have exfiltrated financial data from Lopay's systems, including customer payment details, card information, banking data, transaction history, and payment terminal information belonging to client companies using the platform.
Data the group says was taken
AI dossier — extracted from the leak post- customer payment details
- card information
- banking data
- transaction history
- payment terminal information
- client company financial information
What the group claims
Lopay is a UK-based fintech company that provides a payment platform enabling small and medium-sized enterprises (SMEs) and sole traders to accept credit card and mobile payments, as well as manage their sales and settlements. This includes financial information belonging to client companies, such as customer payment details, card information, banking data, transaction history, and payment terminal information.
Sources
Source
Indexed 5 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

