Skip to main content

Ransomware victim disclosure

All victims

Portman Finance Group

Claimed by GLOBAL SECRET · listed 3 hours ago

209 GB (255,244 Files, 34,852 Folders)
Data size
10,000+ customer passports, hundreds of thousands of personal data records records
Today
Age
since listed · data leaked

Status timeline

  1. ListedAug 10, 2026
  2. Data leakeddate unknown

At a glance

Status
Data leaked
Sector
Finance
Listed on leak site
Aug 10, 2026
Data size
209 GB (255,244 Files, 34,852 Folders)
Records
10,000+ customer passports, hundreds of thousands of personal data records

About the victim

AI dossier — public-source company profile

Portman Finance Group is a UK-based B2B finance broker and lender specializing in SME funding. Since 2007, they have provided tailored financing solutions to over 20,000 businesses and secured over £1.5 billion in funding across various sectors.

Industry
Business & SME Finance Brokerage
Employees
1000-5000
Founded
2007

Attack summary

Severity: critical — Confirmed exfiltration of large-scale regulated data including passports, personal financial records (salaries), employee and customer PII, and database credentials. Finance sector with potential money laundering allegations increases regulatory and reputational risk. 209 GB dataset with 255,000+ files represents significant exposure.

GLOBAL SECRET claims to have exfiltrated 209 GB of data including passwords, database credentials, customer passports, employee personal data (names, addresses, emails, salaries), and evidence of alleged fraudulent schemes and money laundering operations. The group also claims to have contacted employees directly.

critical

Data the group says was taken

AI dossier — extracted from the leak post
  • Customer passports (10,000+)
  • Residential addresses
  • Email addresses
  • Portal credentials and passwords
  • Database access information
  • Employee personal data (names, salaries, income records)
  • Customer personal identifiable information

What the group claims

Specialist business to business finance broker and lender, providing a personal and professional approach to SME funding for over 20,000 businesses and securing over £1.5bn in funding since 2007. Supports limited companies in any sector, working with local independent businesses through to household names.

The leak post

captured from the group's site
Country: United Kingdom | Website: portmanfinancegroup.co.uk | Revenue: £300 Million | Industry: Finance | Employees: 1000-5000 Employees | Properties: 209 GB (255,244 Files, 34,852 Folders)
We uncovered all passwords and access credentials to the company’s portals, identified all of the company’s databases, and exposed the company’s fraudulent schemes and money laundering operations! We also uncovered more than 10,000 customer passports and hundreds of thousands of pieces of personal data, including residential addresses and email addresses. The employees of this company are extremely careless and indifferent toward their work! In addition to the customers, the company’s employees were also affected, and all personal data—including employees’ incomes and salaries—was exposed! We also took care of sending an email to all employees via their personal email accounts, urging them to sue the company and demand compensation!
"Portman Finance Group" - is a specialist business to business finance broker and lender, providing a personal and professional approach to SME funding for over 20,000 businesses and securing over £1.5bn in funding since 2007. We support limited companies in any sec…

Data the group says was taken

  • passwords
  • access credentials
  • databases
  • customer passports
  • personal data
  • residential addresses
  • email addresses
  • employee personal data
  • employee incomes and salaries

Screenshot of the leak post

Leak screenshot for Portman Finance Group

Sources

Source

Indexed 3 hours ago

This page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.

Is this your supplier? Your competitor? You?

Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

Disclosure context

About GLOBAL SECRET

GLOBAL SECRET is an active ransomware group with 19 confirmed victims as of August 2026. It operates a single onion leak site. The limited victim count suggests a relatively early or low-volume operation. The group has been linked to 19 public disclosures across our corpus. The operation is currently active.

Timeline of this disclosure

  • August 10, 2026Portman Finance Group listed by GLOBAL SECRETon the group's public leak site
Data size
209 GB (255,244 Files, 34,852 Folders)
Records
10,000+ customer passports, hundreds of thousands of personal data records

Sector and geography

This disclosure adds to ransomware activity in the Finance sector, which has 108 disclosures indexed across all operators we track. Geographically, Portman Finance Group is reported in United Kingdom, a country with 1,217 ransomware disclosures in our corpus.

If your organisation is affected

A listing by GLOBAL SECRET means Portman Finance Group appeared on a ransomware extortion site and data attributed to it has been published. If this is your organisation, or a supplier you depend on, the priority is to confirm the intrusion and contain it before the window to act closes.

  • Engage your incident-response team and preserve forensic evidence before remediating — do not wipe affected systems first.
  • Force a password reset and revoke active sessions for exposed accounts; rotate any credentials, API keys or certificates that may have been in the stolen data.
  • Assess regulatory notification duties (GDPR, NIS2, sector regulators) — many carry a 72-hour reporting clock from awareness.
  • Report the incident to your national CERT, NCSC (United Kingdom), as required for your jurisdiction.
  • Monitor for the data appearing on GLOBAL SECRET's leak site and across paste and breach channels, and brief downstream partners who may be exposed through you.

How we know this. Darkfield monitors public ransomware leak sites continuously, archiving every new disclosure and the data later released against the victim. Each entry on this page is sourced from the operator's own publication and cross-checked against complementary OSINT feeds (RansomLook, ransomware.live, RansomWatch). We do not collect or host stolen data — only the metadata, timestamps and screenshots needed to make the public disclosure searchable and accountable. Records here are corrected when the original post is edited, retracted, or merged with another disclosure.