Ransomware victim disclosure
← All victimsGate | Crypto Exchange
Claimed by BYOD · listed 5 hours ago
Status timeline
- ListedOct 7, 2026
- Data leakeddate unknown
At a glance
- Group
- BYOD
- Status
- Data leaked
- Country
- Singapore
- Sector
- Financial Services
- Listed on leak site
- Oct 7, 2026
About the victim
AI dossier — public-source company profileGate is a cryptocurrency exchange platform. No additional details about scale, location, or founding date are available from public sources.
- Industry
- Cryptocurrency Exchange
Attack summary
Severity: critical — Confirmed exfiltration of PII at massive scale (12 million users) including phone numbers, location, gender, and sensitive financial data (balances, AUM, profit rates, 2FA indicators). This poses severe identity theft, fraud, and account takeover risks.The BYOD group claims to have exfiltrated data from 12 million users, including personally identifiable information (phone numbers, gender, city, account details) and financial data (balance, VIP tier, AUM, profit rates, verification status). The group threatens further disclosure and demands communication.
Data the group says was taken
AI dossier — extracted from the leak post- Phone numbers
- User nicknames
- Account balances
- VIP tier classification
- 2FA configuration details
- User region
- User IDs
- Gender
- User position
- Assets under management (AUM)
- Profit rates
- Verification status
- City
- Trading strategy
- Account age
- Profile encryption key
What the group claims
12 Million Users, Phone numbers, Nicknames, Balance/VIP Tier List, 2FA Indicator (differentiates, Passkey/Auth) Region, UIDs, Gender, Position, AUM, Profit Rates, Verification Status, City, Strategy, Account Age, Profile Key, and SO much more. This is terrible, for you guys of course, we wonder what will happen if this ever gets out onto the corners of the internet it shouldn't. Anyways, you know where to find us (contact tab). We will take you down when communication has been established between our team and yours.
Source
Indexed 5 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

