Ransomware victim disclosure
← All victimsTriPartum
Claimed by Akira · listed 4 months ago
Status timeline
- ListedFeb 6, 2026
- Data leakeddate unknown
At a glance
- Group
- Akira
- Status
- Data leaked
- Country
- United Kingdom
- Listed on leak site
- Feb 6, 2026
- Data size
- 70 GB
About the victim
AI dossier — public-source company profileTriPartum is a UK-based company specialising in customer communication management and experience. It serves sectors including finance, insurance, utilities, telecommunications, retail, and housing providers, delivering solutions that optimise personalised critical mailings and customer-facing communications.
- Industry
- Customer Communications Management
Attack summary
Severity: critical — Confirmed exfiltration of regulated PII at scale (passports, driving licences, credit card data) affecting employees and customers, plus sensitive financial and contractual data from a company handling critical communications for financial, insurance, and utility sector clients; 70 GB of data is pending publication.Akira claims to have exfiltrated approximately 70 GB of corporate data from TriPartum, including employee personal documents (passports, driving licences, credit card details), financial records, customer information, project files, and NDAs, with publication of the data imminent.
Data the group says was taken
AI dossier — extracted from the leak post- Employee passports
- Employee driving licences
- Employee credit card details
- Employee personal information
- Financial records
- Customer information
- Project files
- NDAs
What the group claims
TriPartum specializes in creating clear and engaging customer com munications for sectors such as finance, insurance, utilities, te lecommunications, retail, and housing providers. They focus on cu stomer communication management and experience, delivering soluti ons that optimize personalized critical mailings. We will upload almost 70gb of corporate data soon. Employee infor mation (passports, DLs and other personal information, credit car ds), financials, customers information, projects, NDAs, etc.
Source
Indexed 4 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

