Ransomware victim disclosure
← All victimsThe GMP Group
Claimed by Nightspire · listed 2 months ago
Status timeline
- ListedApr 1, 2026
- Data leakeddate unknown
At a glance
- Group
- Nightspire
- Status
- Data leaked
- Country
- Singapore
- Listed on leak site
- Apr 1, 2026
About the victim
AI dossier — public-source company profileThe GMP Group is a premier recruitment and HR solutions firm headquartered in Singapore, with over 30 years of experience operating across ASEAN and connecting candidates with employers globally. The company offers end-to-end staffing, professional recruitment, and HR outsourcing services across multiple industries. It is described as one of Asia's leading professional staffing organisations.
- Industry
- Recruitment & HR Staffing Services
- Address
- Singapore
Attack summary
Severity: high — Confirmed exfiltration and publication of sensitive business and personal data including salary records and resumes/CVs (PII at scale for job candidates and employees), plus internal financial documents. As a recruitment firm, the breadth of candidate PII in their possession amplifies the severity significantly.The Nightspire ransomware group claims to have exfiltrated data from The GMP Group, with the disclosed dataset including financial documents, salary records, and candidate resumes/CVs. The status is marked as data_published, indicating the stolen data has been released.
Data the group says was taken
AI dossier — extracted from the leak post- Financial documents
- Salary documents
- Resumes and CVs
What the group claims
- Financial Documents- Salaries Documents- Resumes & CV
Sources
- Victim sitegmprecruit.com
Source
Indexed 2 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

