Ransomware victim disclosure
← All victimsPortman Finance Group
Claimed by GLOBAL SECRET · listed 3 hours ago
Status timeline
- ListedAug 10, 2026
- Data leakeddate unknown
At a glance
- Group
- GLOBAL SECRET
- Status
- Data leaked
- Country
- United Kingdom
- Sector
- Finance
- Listed on leak site
- Aug 10, 2026
- Data size
- 209 GB (255,244 Files, 34,852 Folders)
- Records
- 10,000+ customer passports, hundreds of thousands of personal data records
About the victim
AI dossier — public-source company profilePortman Finance Group is a UK-based B2B finance broker and lender specializing in SME funding. Since 2007, they have provided tailored financing solutions to over 20,000 businesses and secured over £1.5 billion in funding across various sectors.
- Industry
- Business & SME Finance Brokerage
- Employees
- 1000-5000
- Founded
- 2007
Attack summary
Severity: critical — Confirmed exfiltration of large-scale regulated data including passports, personal financial records (salaries), employee and customer PII, and database credentials. Finance sector with potential money laundering allegations increases regulatory and reputational risk. 209 GB dataset with 255,000+ files represents significant exposure.GLOBAL SECRET claims to have exfiltrated 209 GB of data including passwords, database credentials, customer passports, employee personal data (names, addresses, emails, salaries), and evidence of alleged fraudulent schemes and money laundering operations. The group also claims to have contacted employees directly.
Data the group says was taken
AI dossier — extracted from the leak post- Customer passports (10,000+)
- Residential addresses
- Email addresses
- Portal credentials and passwords
- Database access information
- Employee personal data (names, salaries, income records)
- Customer personal identifiable information
What the group claims
Specialist business to business finance broker and lender, providing a personal and professional approach to SME funding for over 20,000 businesses and securing over £1.5bn in funding since 2007. Supports limited companies in any sector, working with local independent businesses through to household names.
The leak post
captured from the group's siteCountry: United Kingdom | Website: portmanfinancegroup.co.uk | Revenue: £300 Million | Industry: Finance | Employees: 1000-5000 Employees | Properties: 209 GB (255,244 Files, 34,852 Folders) We uncovered all passwords and access credentials to the company’s portals, identified all of the company’s databases, and exposed the company’s fraudulent schemes and money laundering operations! We also uncovered more than 10,000 customer passports and hundreds of thousands of pieces of personal data, including residential addresses and email addresses. The employees of this company are extremely careless and indifferent toward their work! In addition to the customers, the company’s employees were also affected, and all personal data—including employees’ incomes and salaries—was exposed! We also took care of sending an email to all employees via their personal email accounts, urging them to sue the company and demand compensation! "Portman Finance Group" - is a specialist business to business finance broker and lender, providing a personal and professional approach to SME funding for over 20,000 businesses and securing over £1.5bn in funding since 2007. We support limited companies in any sec…
Data the group says was taken
- passwords
- access credentials
- databases
- customer passports
- personal data
- residential addresses
- email addresses
- employee personal data
- employee incomes and salaries
Screenshot of the leak post

Sources
Source
Indexed 3 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

