Ransomware victim disclosure
← All victimsMoscord
Claimed by Eclipse · listed 1 day ago
Status timeline
- ListedAug 16, 2026
- Data leakeddate unknown
At a glance
About the victim
AI dossier — public-source company profileMoscord is a digital marketplace platform serving the maritime and oil & gas sectors, connecting buyers and sellers through a network of ports and offices across multiple countries. The company facilitates procurement, logistics, and eCommerce transactions with offices in Singapore, Manila, and Rotterdam, and operates through a global port network spanning Asia-Pacific, Europe, and North America.
- Industry
- Maritime & Oil & Gas Digital Marketplace / Logistics
- Address
- Level 35, The Gateway West, 150 Beach Road, Singapore 189720
Attack summary
Severity: medium — Data published status confirmed but no proof files advertised in the excerpt; no regulated data categories explicitly mentioned; moderate sensitivity of B2B maritime/logistics data and potential customer records.Eclipse claims to have breached Moscord and exfiltrated data. The leak post does not specify whether encryption occurred or detail the scope of data compromised beyond the general assertion of a breach.
Data the group says was taken
AI dossier — extracted from the leak post- company information
- user account data
- maritime/logistics records
What the group claims
Moscord is a digital marketplace that connects buyers and sellers in the maritime industry, offering a platform for various suppliers to aggregate and present their products. The company aims to enhance business operations for its clients by providing innovative solutions in procurement, logistics, and eCommerce. Targeting maritime and oil & gas sectors, Moscord serves a global clientele through its extensive network of ports and offices across multiple countries. With a focus on improving user experience and operational efficiency, Moscord leverages advanced technology and industry expertise to facilitate seamless transactions.
Sources
Source
Indexed 1 day agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

