Ransomware victim disclosure
← All victimsOptionMetrics
Claimed by Karakurt · listed 3 years ago
Status timeline
- Listed
Mar 31, 2023
- Data leaked
At a glance
- Group
- Karakurt
- Status
- Data leaked
- Country
- United States
- Sector
- Construction
- Listed on leak site
- Mar 31, 2023
- Data size
- 450 GB
About the victim
AI dossier — public-source company profileOptionMetrics is a U.S.-based financial data provider specializing in historical options and equity data, offering analytics products used by institutional investors, hedge funds, and academic researchers. The company is known for its IvyDB suite of databases covering implied volatility and options pricing data. It operates as a niche quantitative financial data vendor serving capital markets professionals.
- Industry
- Financial Data & Analytics
- Employees
- 11-50
- Founded
- 1999
Attack summary
Severity: critical — 450 GB of confirmed exfiltrated data including financial records, contracts, employee PII, and proprietary databases from a financial data vendor constitutes a critical disclosure; regulated financial and personal data is at stake and the data has been published.Karakurt claims to have exfiltrated approximately 450 GB of data from OptionMetrics, including financial and accounting data, business contacts, signed contracts, and employee records along with associated databases. The post indicates data has been published, with no mention of encryption.
Data the group says was taken
AI dossier — extracted from the leak post- Financial and accounting data
- Business contacts
- Signed contracts
- Employee information
- Internal databases
What the group claims
OptionMetrics provides its customers with databases of various business directions. They have shared some databases with us also. Here is what we got: great amount of financial and accounting data, business contacts, signed contracts, employees information and that DBs as well, of course. In total you can check 450 GB of sweet data.Have fun!
Sources
Source
Indexed 3 years agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
