DUC App: Global Money Movement, Simplified
bd_aef758251fe31a19 · schema v1 · pii pii-v1
Full breach record for DUC App: Global Money Movement, Simplified →2 incidents on fileThreat-actor claim — not a regulatory filing
This row is a claim by the ransomware group Killsec on its public extortion blog. It has not been validated by the victim or any regulator. Treat attribution and counts as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.
Source: Ransomware.live
Post text · scraped from the leak site
DUC App is a leading financial technology platform that empowers individuals and businesses to manage global payments and currency exchange effortlessly. Offering instant transfers, international mobile top-ups, cryptocurrency transactions, and robust API integrations for e-commerce, DUC App delivers a secure, user-friendly experience across web, iOS, and Android devices -- The data includes, but is not limited to, clients' home addresses, phone numbers, transaction histories, email addresses, public and private crypto address keys, verified documents, passports, IDs, and more. If the company refuses to cooperate, we will release all information.
J jump to incidentP pin to compareR raw source
Incident timeline — mostly unverified
? — ?
Breach window unknown
Oct 23, 2025
Claim posted
—
No filing yet · watching
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Claim → filing
—
Compliance clock
Not assessable
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.
No regulatory filing corroborates this yet — it is the attacker's own assertion. Watch this entity to be notified the moment a filing corroborates or contradicts it.
Source ceiling
- actor name
- victim claim
- ransom/leak status
- discovery date
- materiality
- notification
- affected count
- confirmed data types
- compliance clock
The ✕ fields stay blank until a regulatory filing or victim disclosure lands.
killsec
According to ransomware.live, KillSec originated as a hacktivist group aligned with the Anonymous movement before pivoting to ransomware operations in October 2023, officially launching a RaaS platform in June 2024 with an affiliate-friendly 88% revenue split, primarily targeting healthcare, financial services, and government sectors with over 250 documented victims as of late 2025.