Ransomware victim disclosure
← All victimsAbrigo, Inc.
Claimed by shinyhunters · listed 1 month ago
Status timeline
- Listed
Apr 12, 2026
- Data leaked
At a glance
- Group
- shinyhunters
- Status
- Data leaked
- Country
- US
- Sector
- Financial Services
- Listed on leak site
- Apr 12, 2026
About the victim
AI dossier — public-source company profileAbrigo, Inc. is a U.S.-based financial technology company that provides software and advisory solutions to community banks, credit unions, and financial institutions. Their platform covers areas such as lending, risk management, compliance, and anti-money laundering. The company serves thousands of financial institutions across the United States.
- Industry
- Financial Technology & Banking Software
- Employees
- 501-1000
- Founded
- 2018
Attack summary
Severity: critical — The claimed exfiltration of over 1.7 million Salesforce records containing PII from a financial technology company serving banks and credit unions constitutes a large-scale regulated data exposure, with downstream risk to financial institutions and their customers.ShinyHunters claims to have exfiltrated over 1.7 million Salesforce records containing PII and internal corporate data from Abrigo, Inc., and has issued a final warning threatening to publish the data if payment is not received by 14 April 2026.
Data the group says was taken
AI dossier — extracted from the leak post- Salesforce CRM records
- Personally Identifiable Information (PII)
- Internal corporate data
What the group claims
Over 1.7M Salesforce records containing PII and other internal corporate data have been compromised. Pay or leak. This is a final warning to reach out by 14 Apr 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 11 Apr 2026 | Warning: FINAL WARNING PAY OR LEAK
Source
Indexed 1 month agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
