Disney Family
bd_b1d8affdb7a55772 · schema v1 · pii pii-v1
Full breach record for Disney Family →Threat-actor claim — not a regulatory filing
This row is a claim by the ransomware group Thegentlemen on its public extortion blog. It has not been validated by the victim or any regulator. Treat attribution and counts as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.
Source: Ransomware.live
Post text · scraped from the leak site
This critical data breach involves Disney Family / Shamrock Holdings, the private investment firm and family office established by Roy E. Disney to manage the wealth of the Disney family branch, rather than the public Walt Disney Company. The compromised dataset, totaling over 800 GB and spanning from the 1980s to June 2026, exposes highly sensitive information across 14 critical categories, including family trusts, tax administration, and private equity fund management. Key victims include prominent figures such as Abigail Disney, Roy P. Disney, and Stanley Gold, whose personal financial records, passports, and KYC documents were leaked alongside detailed trust instruments for the "Disney Grandchildren Trusts." The breach reveals active operational data, including recent payroll records, bank reconciliations with CNB, and subscription agreements for funds like the Shamrock Israel Growth Fund. With unencrypted databases, embedded ERP credentials etc..
Source provenance
- Source URL
- https://www.ransomware.live/id/RGlzbmV5IEZhbWlseUB0aGVnZW50bGVtZW4=
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jul 23, 2026
- Raw hash
- 441868f98915cff7ad641447f2727e5c2bdb2edd732d83c9510a7c1d58865298
Reporting entity
- Name
- thegentlemen
Victim entity
- Name
- Disney Familynorm: disney family
What this source establishes
- Source ceiling
- A leak-site claim can't tell us: discovery date · materiality · notification · affected count · confirmed data types · compliance clock. These stay blank until a regulatory filing or victim disclosure lands.
- Attack vector
- Ransomware· thegentlemen
- Threat actor
- ThegentlemenExternalFinancial
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.