Ransom! SpearFin Ltd (AUG-2026)

Ransom! SpearFin Ltd (AUG-2026)
SpearFin Ltd (MU) in Mauritius, a fund administration and corporate services provider with ~US$10 billion in assets under administration, disclosed a data leak attributed to ransomware threat actor incransom on June 26, 2026, totaling 416 GB of confidential material including KYC/AML records, passports, bank statements, shareholder and directors registers, and related investment and corporate agreements. Affected data includes documents such as NDAs, investing documents, application forms, certificates (including GBC certifications), loans and payroll records, and correspondence tied to multiple clients; #Mauritius

Incident Details

  • Victim: SpearFin Ltd
  • Sector: Financial Services
  • Country: MU
  • Actor: incransom
  • Source: http://incblog6qu4y4mm4zvw5nrmue6qbwtgjsxpw6b7ixzssu36tsajldoad.onion/blog/disclosures/6a84277a9cd108bf265a45d9
  • Discovered: 2026-08-18T10:27:05.942796+00:00
  • Published: 2026-08-18T01:00:00+00:00

Information

  • SpearFin Ltd, a Mauritius-based firm, provides fund administration, corporate services, compliance support, and investor relations, with assets under administration of US$10 billion.
  • The leak occurred on June 26, 2026, with a total volume of 416 GB.
  • The exposed data included NDAs, client correspondence, KYC passports, certificates, investment documents, share registries and holders, AML audit materials, agreements, application forms, bank statements, payroll records, loan documents, GBC certificates, and registers of directors.
  • The leaked materials also referenced clients such as YuMee Seven Six, BAMBOO BAY PRIVATE LIMITED, Asio Global Fund, 3B Capital, Abans Group, Amicorp Capital, Apex Fund Services Ltd, Pangaea Fund Limited, and others.
  • The information was classified as confidential.
  • Full publication was announced as coming soon.

Disclaimer: This post is based on public claims made by the ransomware group "incransom". I cannot confirm the accuracy of the information. However, I would be happy to share any official statement from the affected organization to provide clarification.

monitored by: ransomware.live