Ransomware victim disclosure
← All victimsAban Tether & OK exchange
Claimed by Arvinclub · listed 3 years ago
Status timeline
- Listed
Sep 2, 2023
- Data leaked
At a glance
- Group
- Arvinclub
- Status
- Data leaked
- Country
- Iran
- Sector
- Financial Services
- Listed on leak site
- Sep 2, 2023
About the victim
AI dossier — public-source company profileAban Tether and OK Exchange appear to be Iranian cryptocurrency exchange platforms, with Aban Tether (abantether.com) likely focused on Tether (USDT) trading and OK Exchange (ok-ex.io) operating as a broader crypto trading platform. Both operate within Iran's financial services sector, serving retail and possibly institutional crypto users. No further verifiable details are available from the provided site content.
- Industry
- Cryptocurrency Exchange & Trading
Attack summary
Severity: high — Cryptocurrency exchanges handle sensitive financial data, KYC/PII, and wallet information at scale. Data_published status indicates confirmed exfiltration and release, which is significant even without a captured leak post detailing the scope.The Arvinclub ransomware group claims to have attacked Aban Tether and OK Exchange, with the disclosure status indicating data has been published. No specific details on encryption, exfiltration methods, or data volume are available from the captured leak post.
Data the group says was taken
AI dossier — extracted from the leak post- User account records
- Financial transaction data
- KYC/identity verification documents
- Cryptocurrency wallet information
Sources
- Victim siteabantether.com https://ok-ex.io
Source
Indexed 3 years agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
