Etfsa
bd_7526a28fe7ec8998 · schema v1 · pii pii-v1
Full breach record for Etfsa →Threat-actor claim — not a regulatory filing
This row is a claim by the ransomware group INC Ransom on its public extortion blog. It has not been validated by the victim or any regulator. Treat attribution and counts as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.
Source: Ransomware.live
Post text · scraped from the leak site
ETFSA.co.za is a South African financial services platform specializing in exchange-traded funds (ETFs). It offers a wide range of investment options, allowing individuals to invest in various sectors, indices, and asset classes through low-cost, diversified ETFs. The platform provides educational resources, investment solutions, and tools to help investors manage their portfolios effectively. ETFSA also supports tax-free savings accounts (TFSA) and retirement accounts, making it accessible for long-term wealth building ETFSA.co.za became the target of a cyberattack, and all confidential and personal client data will be published soon. Mike Brown did not worry about the security of his clients' data; he had the opportunity to ensure the safety of such sensitive data, but he preferred to stay on the sidelines. +27 82 653 5645 (m) Mike Brown
Source provenance
- Source URL
- https://www.ransomware.live/id/RVRGU0FAaW5jcmFuc29t
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 25, 2026
- Raw hash
- 64e0ff1978682b03823c9e9e2ce499576cd0d6bacfc5d0c95b8a49d7786dea77
Reporting entity
- Name
- incransomnorm: inc_ransom
Victim entity
- Name
- Etfsanorm: etfsa
- Domain
- etfsa.co.za
- Industry
- Financial Services
What this source establishes
- Source ceiling
- A leak-site claim can't tell us: discovery date · materiality · notification · affected count · confirmed data types · compliance clock. These stay blank until a regulatory filing or victim disclosure lands.
- Attack vector
- Ransomware· inc_ransom
- Threat actor
- Inc RansomExternalFinancial
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.