Ransomware victim disclosure
← All victimsThe GMP Group
Claimed by NIGHT SPIRE · listed 18 hours ago
Status timeline
- Listed
Jun 6, 2026
Current state: Listed for ransom
At a glance
- Group
- NIGHT SPIRE
- Status
- Listed for ransom
- Country
- Singapore
- Sector
- Recruitment/Staffing
- Listed on leak site
- Jun 6, 2026
- Data size
- 600 GB
About the victim
AI dossier — public-source company profileThe GMP Group is a premier Singapore-based recruitment and HR solutions firm with over 30 years of experience in ASEAN talent acquisition. They provide comprehensive recruitment services, HR solutions, and industry-specific staffing expertise to companies globally.
- Industry
- Recruitment & Staffing Services
- Address
- Singapore
Attack summary
Severity: high — Confirmed exfiltration of 600 GB including sensitive PII at scale (candidate information, employee salaries, HR records, financial data). Recruitment firms process extensive personal data of job candidates and employees, making this a significant breach of regulated information.NIGHT SPIRE claims to have exfiltrated approximately 600 GB of data including financial documents, HR records, employee salaries, candidate personally identifiable information (PII), resumes, and CVs. The group lists the data as disclosed but indicates specific files are currently unavailable.
Data the group says was taken
AI dossier — extracted from the leak post- Financial documents
- Salary documents
- Candidate PII and resumes
- HR data and employee records
- Supervisor information
- Email and SMS data
- Banking and financial records
- Accounting and tax records
- Contracts and proposals
- Business strategy files
- HR and employee personal data
What the group claims
Premier Singapore Recruitment Firm with Global Reach
The leak post
captured from the group's site- Financial Documents- HR Data- Supervisor's Information Data is not available now. Data is not available now. Data is not available now. [la familia adualt day center](http://www.lafamiliaadultdaycenter.com) Data is not available now. Data is not available now. - QuickBooks Files- Scanned tax returns- Proposal, Contrats- QuickBooks automated backups - Banking & Financial Records- Personal data- Critical POS Data - Banking & Financial Data- Accounting & Tax Records - Financial & Accounting Records- Human Resources- Sales & Marketing - Sales Related Documents- Human Resources- Sensitive Employee Records- Email and SMS Data Data is not available now. - Technical Documents- Financial Sheets- Contracts & Invoices- Business strategy files - MSSQL-DB- HR Documents- Contracts Data is not available now. [Progressive Oral Surgery & Implantology](http://nspirep7orjq73k2x2fwh2mxgh74vm2now6cdbnnxjk2f5wn34bmdxad.onion/progressiveoralsurgery.com) - Patients Information Records- Financial Records [The Country Club of Darien](http://nspirep7orjq73k2x2fwh2mxgh74vm2now6cdbnnxjk2f5wn34bmdxad.onion/CCDarien.org) - Sales / agent / commercial operations- Industrial / manufacturing / tooling business dat…
Data the group says was taken
- Financial Documents
- Salaries Documents
- Candidate PII information
- Resumes & CV
Screenshot of the leak post

Sources
Source
Indexed 18 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.
