Ransomware victim disclosure
← All victimsNACS (Hong Kong) Limited
listed as nacs.com.hk · Claimed by krybit · listed 2 days ago
Status timeline
- Listed
May 19, 2026
- Data leaked
At a glance
About the victim
AI dossier — public-source company profileNACS (nacs.com.hk) is a Hong Kong-based corporate and administrative services firm specialising in company formation, legal compliance, and accounting services for international clients. The company operates within the financial and administrative services sector, assisting businesses with incorporation and ongoing corporate governance requirements in Hong Kong. It appears to be a well-established provider catering primarily to cross-border or multinational clientele.
- Industry
- Corporate & Administrative Services (Company Formation & Accounting)
- Address
- Hong Kong
Attack summary
Severity: high — The company handles sensitive corporate, legal, and financial records for international clients; confirmed data publication by the threat actor suggests exfiltration of business-sensitive and potentially regulated client data at meaningful scale.The Krybit ransomware group claims to have attacked nacs.com.hk and has published data (disclosed status: data_published), indicating exfiltration of company and client records; no ransom amount or specific data volume has been stated.
Data the group says was taken
AI dossier — extracted from the leak post- Corporate formation records
- Client legal documents
- Accounting records
- International client information
- Administrative service files
What the group claims
nacs.com.hk is a Hong Kong-based corporate and administrative services company, specializing in company formation and ma...
The leak post
captured from the group's sitenacs.com.hk is a Hong Kong-based corporate and administrative services company, specializing in company formation and managing the legal and accounting aspects for international clients. The company appears to be well-established within the financial and administrative services sector
Screenshot of the leak post

Sources
Source
Indexed 2 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
