Ransomware victim disclosure
← All victimsChokChey Finance
Claimed by Incransom · listed 4 months ago
Status timeline
- ListedFeb 2, 2026
- Data leakeddate unknown
At a glance
- Group
- Incransom
- Status
- Data leaked
- Country
- Cambodia
- Sector
- Financial Services
- Listed on leak site
- Feb 2, 2026
About the victim
AI dossier — public-source company profileChokChey Finance PLC is a microfinance institution based in Cambodia, established in 2015 and licensed by the National Bank of Cambodia in 2016. The company offers financial products including speed loans, agriculture loans, SME loans, and mobile device loans, primarily targeting low to moderate income families.
- Industry
- Microfinance & Consumer Lending
- Address
- Cambodia
- Founded
- 2015
Attack summary
Severity: high — ChokChey Finance is a licensed microfinance institution holding regulated financial and personal data on low-to-moderate income borrowers; confirmed data publication by the threat actor implies exfiltration of sensitive financial PII, warranting a high severity rating. Insufficient detail to escalate to critical without confirmed scale of records.The Incransom group claims to have attacked ChokChey Finance PLC and has published data (disclosed status: data_published), though specific details on encryption or the volume of exfiltrated data are not stated in the post.
Data the group says was taken
AI dossier — extracted from the leak post- Customer financial records
- Loan application data
- Personal identification information
- Banking/account data
What the group claims
ChokChey Finance PLC is a microfinance institution based in Cambodia, established in 2015 and licensed by the National Bank of Cambodia in 2016. The company offers a variety of financial products including speed loans, agriculture loans, SME loans, and mobile device loans, targeting low to moderate income families
Sources
Source
Indexed 4 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

