Skip to main content

Ransomware victim disclosure

All victims

Cadorim

Claimed by Kill Security 3.0 · listed 3 months ago

600 GB
Data size
2m
Age
since listed · data leaked

Status timeline

  1. ListedJun 4, 2026
  2. Data leakeddate unknown

At a glance

Status
Data leaked
Country
Belgium
Listed on leak site
Jun 4, 2026
Data size
600 GB

About the victim

AI dossier — public-source company profile

Cadorim is a money transfer platform headquartered in Brussels, Belgium, with operations in Nouakchott, Mauritania. The company specializes in enabling secure international money transfers to Mauritania, offering a user-friendly platform designed for individuals and businesses seeking fast, affordable, and accessible cross-border transactions.

Industry
Financial Services / Money Transfer
Address
Brussels, Belgium (headquarters); Nouakchott, Mauritania (operations)

Attack summary

Severity: high — Confirmed exfiltration of 600 GB from a financial services / money transfer company. Such breaches typically involve customer personal information, transaction history, and potentially banking details, which constitute sensitive financial and personally identifiable data at scale.

Kill Security 3.0 claims to have exfiltrated 600 GB of data from Cadorim. The group has published the data but has not specified which categories of customer or operational data were compromised.

high

Data the group says was taken

AI dossier — extracted from the leak post
  • Customer account information
  • Transaction records
  • Financial data
  • Operational files

What the group claims

Cadorim simplifies money transfers to Mauritania, offering a secure, user-friendly platform for individuals and businesses, headquartered in Brussels with operations in Nouakchott, Mauritania.

The leak post

captured from the group's site
Founded in 1997, iCare Software, based in the United States, delivers innovative management solutions for childcare and afterschool programs. Serving childcare centers, preschools, afterschool programs, and multi-site operations, iCare automates critical tasks like attendance tracking, staff scheduling, tuition collection, and compliance reporting. Its unique offerings include AI-driven analytics, business intelligence dashboards, and CRM tools to boost enrollment and staff retention. With seamless data migration and robust back-end technology, iCare empowers providers to focus on quality care while streamlining operations and driving growth.
Cadorim simplifies money transfers to Mauritania, offering a secure, user-friendly platform for individuals and businesses. With a focus on speed, affordability, and accessibility, Cadorim enables seamless transactions in just three clicks, available around the clock. The company ensures maximum security for every transfer, provides competitive exchange rates with no fees, and processes transactions instantly. Headquartered in Brussels, Belgium, with operations in Nouakchott, Mauritania, Cadorim serves customers seeking reliable, cost-effectiv…

Screenshot of the leak post

Leak screenshot for Cadorim

Sources

Source

Indexed 3 months ago

This page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.

Is this your supplier? Your competitor? You?

Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

Disclosure context

About Kill Security 3.0

Kill Security 3.0 is a financially motivated ransomware group first observed in June 2026, representing an apparent iteration or rebranding of an earlier Kill Security lineage, with operational activity documented against at least 11 confirmed victims across multiple countries and sectors. Given the limited open-source intelligence available on this group at this time, attribution to a specific country of origin or affiliation with known threat actor clusters has not been publicly confirmed by CISA, the FBI, Mandiant, or other reputable security research organizations; however, the group's targeting patterns suggest deliberate sector selection consistent with data-rich, operationally sensitive environments. Based on observed victim telemetry, Kill Security 3.0 has demonstrated a preference for targeting organizations in the United States, United Kingdom, Canada, South Korea, and Morocco, with particular focus on healthcare technology and medical device companies, childcare management software providers, financial services and debt recovery firms, legal services organizations, and behavioral health tracking platforms — a targeting profile that suggests an interest in sensitive personal, financial, and medical data likely leveraged for double extortion purposes. No specific initial access vectors, encryption methodologies, or tooling have been publicly attributed to this group by authoritative sources as of the time of this writing, though the sector focus on data-sensitive industries is consistent with exfiltration-prior-to-encryption tactics commonly employed by contemporary ransomware operators. No major named campaigns, record ransom demands, or law enforcement actions against Kill Security 3.0 have been publicly documented, and its current operational status remains active based on first-observed dating, though the limited victim count suggests the group may still be in early operational phases or selectively targeting victims. The group has been linked to 11 public disclosures across our corpus. First observed on a leak site on June 4, 2026. The operation is currently active.

Timeline of this disclosure

  • June 4, 2026Cadorim listed by Kill Security 3.0on the group's public leak site
Data size
600 GB

Sector and geography

This disclosure adds to ransomware activity in the Financial Services / Money Transfer sector. Geographically, Cadorim is reported in Belgium, a country with 90 ransomware disclosures in our corpus.

If your organisation is affected

A listing by Kill Security 3.0 means Cadorim appeared on a ransomware extortion site and data attributed to it has been published. If this is your organisation, or a supplier you depend on, the priority is to confirm the intrusion and contain it before the window to act closes.

  • Engage your incident-response team and preserve forensic evidence before remediating — do not wipe affected systems first.
  • Force a password reset and revoke active sessions for exposed accounts; rotate any credentials, API keys or certificates that may have been in the stolen data.
  • Assess regulatory notification duties (GDPR, NIS2, sector regulators) — many carry a 72-hour reporting clock from awareness.
  • Report the incident to your national CERT, CERT.be (Belgium), as required for your jurisdiction.
  • Monitor for the data appearing on Kill Security 3.0's leak site and across paste and breach channels, and brief downstream partners who may be exposed through you.

How we know this. Darkfield monitors public ransomware leak sites continuously, archiving every new disclosure and the data later released against the victim. Each entry on this page is sourced from the operator's own publication and cross-checked against complementary OSINT feeds (RansomLook, ransomware.live, RansomWatch). We do not collect or host stolen data — only the metadata, timestamps and screenshots needed to make the public disclosure searchable and accountable. Records here are corrected when the original post is edited, retracted, or merged with another disclosure.