Ransomware victim disclosure
← All victimsvouch.co.uk + KYC UK
Claimed by stormous · listed 19 days ago
Status timeline
- Listed
May 2, 2026
- Data leaked
At a glance
- Group
- stormous
- Status
- Data leaked
- Country
- GB
- Sector
- Financial Services
- Listed on leak site
- May 2, 2026
About the victim
AI dossier — public-source company profileVouch (vouch.co.uk), operating alongside KYC UK, is a UK-based financial services company involved in identity verification and Know Your Customer (KYC) processes. The company collects and stores personal identity documentation and customer data as part of its compliance and verification services. No additional public site content was available to further characterise its scale or precise operations.
- Industry
- Financial Services & KYC Compliance
Attack summary
Severity: critical — The exfiltrated data includes government-issued identity documents (UK ID cards) and KYC records, constituting regulated PII at scale. This falls squarely within critical-severity criteria due to confirmed exfiltration of identity-verification data and biographic information, which carries high risk of identity fraud and regulatory breach under UK GDPR.The Stormous ransomware group claims to have exfiltrated approximately 3GB of data from Vouch/KYC UK, including KYC records, UK ID card scans, email addresses, phone numbers, and full names. No encryption claim was made; the disclosure status indicates the data has been published.
Data the group says was taken
AI dossier — extracted from the leak post- KYC information
- UK ID card scans
- Email addresses
- Phone numbers
- Full names
What the group claims
Vouch does not protect its customers' data at all and stores it poorly. Many users' data, including KYC information, UK ID cards, email addresses, phone numbers, full names, and more, have been extracted. Approximately 3GB of data was collected.
Source
Indexed 19 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
