Ransomware victim disclosure
← All victimsAnvil Arts
listed as anvilarts.org.uk · Claimed by m3rx · listed 22 days ago
Status timeline
- Listed
Apr 29, 2026
- Data leaked
At a glance
- Group
- m3rx
- Status
- Data leaked
- Country
- GB
- Sector
- Consumer Services
- Listed on leak site
- Apr 29, 2026
About the victim
AI dossier — public-source company profileAnvil Arts is an independent educational charitable trust (The Anvil Trust Limited) and the largest performing arts organisation in Hampshire, UK. It operates three venues in Basingstoke, including The Anvil and The Haymarket, hosting a diverse range of music, theatre, and cultural performances. The organisation relies on donations and is registered under Charity No. 1034961.
- Industry
- Performing Arts & Cultural Venues
- Address
- Churchill Way, Basingstoke, Hampshire RG21 7QR, United Kingdom
Attack summary
Severity: high — 480 GB / 299,000 files have been confirmed as exfiltrated and published. As a charitable arts organisation, this data likely includes PII of donors, customers, and staff at significant scale, constituting a major data breach warranting high severity.The group m3rx claims to have exfiltrated approximately 480 GB of data comprising around 299,000 files from Anvil Arts, with the data now published. No encryption claim is stated; the disclosure indicates confirmed data exfiltration.
Data the group says was taken
AI dossier — extracted from the leak post- Organisational files (299k files, 480 GB)
- Potential donor/supporter records
- Potential staff and employment records
- Potential financial and booking records
- Potential personal data of customers/patrons
What the group claims
Anvil Arts is the largest performing arts organization in Hampshire, operating as an independent charitable trust. It manages three venues in Basingstoke, including The Anvil and The Haymarket, providing a diverse range of performances and cultural events. Stolen: 480gb 299k files
The leak post
captured from the group's siteIf you are interested in this data, please contact our support.Tox: 9A1217BEDA4AB77052A25D17CB6FFB34AFA2BE462E607F2FD8E1DF1DDD4CA16A64E18B1A0BF2
Sources
Source
Indexed 22 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
