Ransomware victim disclosure
← All victimsTIW Group
listed as tiw-group.com · Claimed by devman · listed 4 months ago
Status timeline
- Listed
Jan 28, 2026
- Data leaked
At a glance
- Group
- devman
- Status
- Data leaked
- Country
- SJ
- Sector
- Technology
- Listed on leak site
- Jan 28, 2026
About the victim
AI dossier — public-source company profileTIW Group is a specialist software firm with over 30 years of experience developing solutions for the insurance industry. Their flagship product, ALIS, provides end-to-end processing for life insurance and annuities. They also offer business process automation, legacy modernization, and risk compliance management services.
- Industry
- Insurance Software & IT Solutions
Attack summary
Severity: high — Data has been published (not merely threatened), and TIW Group handles insurance industry software including life insurance and annuity processing, meaning exfiltrated data likely includes sensitive financial and policyholder-related information from their clients or platform.The group 'devman' claims to have published data obtained from TIW Group, with the disclosure status listed as data_published, indicating exfiltration and public release of company data.
Data the group says was taken
AI dossier — extracted from the leak post- Insurance industry client data
- Software source code or proprietary product data (ALIS platform)
- Business process and operational records
- Risk compliance documentation
Original description
AI-summarised, not from the leak postTIW Group is a specialist software firm with over 30 years of experience in developing solutions for the insurance industry. Their flagship product, ALIS, provides end-to-end solutions for life insurance and annuity processing. Additionally, they provide business process automation, legacy modernization, and risk compliance management services. Their digital solutions help businesses to streamline operations and improve business efficiency.
Sources
Source
Indexed 4 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
