Ransomware victim disclosure
← All victimsPalmgold Management Sdn Bhd
Claimed by crypto24 · listed 9 months ago
Status timeline
- Listed
Aug 18, 2025
- Data leaked
At a glance
About the victim
AI dossier — public-source company profilePalmgold Management Sdn Bhd is a Malaysian company operating a Casino Division with gaming operations and a Credit Division (pgcredit.com.my) providing credit/financial services. The company maintains member databases, gaming infrastructure, and financial transaction systems across multiple branches.
- Industry
- Gaming & Financial Services
Attack summary
Severity: critical — Confirmed exfiltration and publication of regulated financial and gaming data at scale, including PII of 60,000+ casino members, complete KYC records, banking/transaction data, and sensitive operational intelligence. Involves both gaming and financial services sectors with clear personal and financial data exposure.The crypto24 group claims to have exfiltrated over 500 GB of data from both casino and credit divisions, including operational databases with member PII, gaming analytics, financial records, KYC information, and banking transaction data. The group has published the exfiltrated data.
Data the group says was taken
AI dossier — extracted from the leak post- Casino member database (60,000+ records with PII)
- Jackpot and play history
- Betting patterns and analytics
- Slot machine configurations and volatility settings
- Power BI dashboards and internal analytics
- Finance and HR documents
- IT documents
- Scanner share contents from branches
- Promotion formulas and revenue models
- Fraud detection criteria and blacklists
- KYC customer information
- Banking and cash transaction records
What the group claims
We have exfiltrated over 500GB of most sensitive and business-critical data from palmgold's internal network. This includes data from both the Casino Division and the Credit Division, where the Casino Division holds the full operational database of over 60,000 members including PII, jackpot and play history, betting patterns, machine configurations, Power BI dashboards used for internal analytics, confidential finance, HR, and IT documents, complete scanner share contents from all branches (kmscan, toshibascan, fujiscan), as well as operational logic such as promotion formulas, game-specific revenue models, slot machine volatility settings, player-tier betting analytics, risk thresholds, fraud alert triggers, and blacklist criteria, while the Credit Division (pgcredit.com.my) contains all customer KYC information along with detailed banking and cash transaction records.
Sources
- Victim sitepalmgold-mgmt.com
Source
Indexed 9 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
