Skip to main content

Ransomware victim disclosure

All victims

MortDash

Claimed by Kill Security 3.0 · listed 3 months ago

600 GB
Data size
2m
Age
since listed · data leaked

Status timeline

  1. ListedJun 4, 2026
  2. Data leakeddate unknown

At a glance

Status
Data leaked
Listed on leak site
Jun 4, 2026
Data size
600 GB

About the victim

AI dossier — public-source company profile

MortDash is a US-based software company that provides a cloud-native, AI-powered operating system for wholesale mortgage operations. It serves wholesale lenders, brokers, and non-delegated correspondent lenders, automating end-to-end mortgage workflows including lead generation, broker onboarding, document handling, compliance, and analytics.

Industry
Financial Technology / Mortgage Operations

Attack summary

Severity: critical — Exfiltration of 600 GB of data from a mortgage operations platform serving lenders and brokers. Data likely includes sensitive financial records, client PII, loan documents, and compliance information affecting multiple financial institutions and consumers.

Kill Security 3.0 claims to have exfiltrated 600 GB of data from MortDash. The group has published the data and provided descriptions of the victim company, indicating confirmed data exfiltration.

critical

Data the group says was taken

AI dossier — extracted from the leak post
  • mortgage operations data
  • lead generation records
  • broker onboarding information
  • document handling systems
  • compliance records
  • mortgage pipeline analytics

What the group claims

MortDash offers a cloud-native, AI-powered operating system for wholesale mortgage operations, serving wholesale lenders, brokers, and non-delegated correspondent lenders.

The leak post

captured from the group's site
Founded in 1997, iCare Software, based in the United States, delivers innovative management solutions for childcare and afterschool programs. Serving childcare centers, preschools, afterschool programs, and multi-site operations, iCare automates critical tasks like attendance tracking, staff scheduling, tuition collection, and compliance reporting. Its unique offerings include AI-driven analytics, business intelligence dashboards, and CRM tools to boost enrollment and staff retention. With seamless data migration and robust back-end technology, iCare empowers providers to focus on quality care while streamlining operations and driving growth.
Cadorim simplifies money transfers to Mauritania, offering a secure, user-friendly platform for individuals and businesses. With a focus on speed, affordability, and accessibility, Cadorim enables seamless transactions in just three clicks, available around the clock. The company ensures maximum security for every transfer, provides competitive exchange rates with no fees, and processes transactions instantly. Headquartered in Brussels, Belgium, with operations in Nouakchott, Mauritania, Cadorim serves customers seeking reliable, cost-effectiv…

Screenshot of the leak post

Leak screenshot for MortDash

Sources

Source

Indexed 3 months ago

This page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.

Is this your supplier? Your competitor? You?

Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

Disclosure context

About Kill Security 3.0

Kill Security 3.0 is a financially motivated ransomware group first observed in June 2026, representing an apparent iteration or rebranding of an earlier Kill Security lineage, with operational activity documented against at least 11 confirmed victims across multiple countries and sectors. Given the limited open-source intelligence available on this group at this time, attribution to a specific country of origin or affiliation with known threat actor clusters has not been publicly confirmed by CISA, the FBI, Mandiant, or other reputable security research organizations; however, the group's targeting patterns suggest deliberate sector selection consistent with data-rich, operationally sensitive environments. Based on observed victim telemetry, Kill Security 3.0 has demonstrated a preference for targeting organizations in the United States, United Kingdom, Canada, South Korea, and Morocco, with particular focus on healthcare technology and medical device companies, childcare management software providers, financial services and debt recovery firms, legal services organizations, and behavioral health tracking platforms — a targeting profile that suggests an interest in sensitive personal, financial, and medical data likely leveraged for double extortion purposes. No specific initial access vectors, encryption methodologies, or tooling have been publicly attributed to this group by authoritative sources as of the time of this writing, though the sector focus on data-sensitive industries is consistent with exfiltration-prior-to-encryption tactics commonly employed by contemporary ransomware operators. No major named campaigns, record ransom demands, or law enforcement actions against Kill Security 3.0 have been publicly documented, and its current operational status remains active based on first-observed dating, though the limited victim count suggests the group may still be in early operational phases or selectively targeting victims. The group has been linked to 11 public disclosures across our corpus. First observed on a leak site on June 4, 2026. The operation is currently active.

Timeline of this disclosure

  • June 4, 2026MortDash listed by Kill Security 3.0on the group's public leak site
Data size
600 GB

Sector and geography

This disclosure adds to ransomware activity in the Financial Technology / Mortgage sector. Geographically, MortDash is reported in United States, a country with 11,033 ransomware disclosures in our corpus.

If your organisation is affected

A listing by Kill Security 3.0 means MortDash appeared on a ransomware extortion site and data attributed to it has been published. If this is your organisation, or a supplier you depend on, the priority is to confirm the intrusion and contain it before the window to act closes.

  • Engage your incident-response team and preserve forensic evidence before remediating — do not wipe affected systems first.
  • Force a password reset and revoke active sessions for exposed accounts; rotate any credentials, API keys or certificates that may have been in the stolen data.
  • Assess regulatory notification duties (GDPR, NIS2, sector regulators) — many carry a 72-hour reporting clock from awareness.
  • Report the incident to your national CERT, CISA (United States), as required for your jurisdiction.
  • Monitor for the data appearing on Kill Security 3.0's leak site and across paste and breach channels, and brief downstream partners who may be exposed through you.

How we know this. Darkfield monitors public ransomware leak sites continuously, archiving every new disclosure and the data later released against the victim. Each entry on this page is sourced from the operator's own publication and cross-checked against complementary OSINT feeds (RansomLook, ransomware.live, RansomWatch). We do not collect or host stolen data — only the metadata, timestamps and screenshots needed to make the public disclosure searchable and accountable. Records here are corrected when the original post is edited, retracted, or merged with another disclosure.

MortDash data breach — Kill Security 3.0 ransomware leak (2026) · Darkfield