[Redacted by threat actor]
bd_d3076a304ce554da · schema v1 · pii pii-v1
Threat-actor claim — not a regulatory filing
This row is a claim by the ransomware group Thegentlemen on its public extortion blog. It has not been validated by the victim or any regulator. Treat attribution and counts as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.
Source: Ransomware.live
Post text · scraped from the leak site
1.5 terabytes of data stolen from one of Asia's largest investment companies, with more than 10 billion USD under management. The stolen data includes: 1. Investment documentation: private placement memorandums, investment memos (Pre-IC/Final-IC), financial models and project budgets 2. Investor database (LP): complete limited partner information, investment terms, contacts, non-disclosure agreements 3. Portfolio companies: financial statements, strategic plans and operating metrics for 30+ companies under management 4. Active M&A deals: documentation on 9+ projects, including due diligence and asset valuations 5. Corporate finances: salaries and bonuses for all employees (150+ people), department budgets, financial results 2022-2025 6. Strategic documents: Management Committee materials, top management biographies, corporate strategy, ESG policies 7. Legal documents: counterparty contracts, partner NDAs, regulatory documentation 8. Email correspondence: 500+ email files with deal approvals, negotiations and confidential management communications 9. CEO Office documents: leadership personal files and critical corporate secrets
Source provenance
- Source URL
- https://www.ransomware.live/id/KioqLioqKiBMQVNUIFRJTUVSIFVQREFURUB0aGVnZW50bGVtZW4=
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 10, 2025
- Raw hash
- 238e818716897d0027bc41710fe45f4f35eafb3bcb93b2e4608b5116abb3afe0
Reporting entity
- Name
- thegentlemen
Victim entity
- Name
- [Redacted by threat actor]norm: redacted-54ca420a
- Industry
- Financial Servicesllm
What this source establishes
- Source ceiling
- A leak-site claim can't tell us: discovery date · materiality · notification · affected count · confirmed data types · compliance clock. These stay blank until a regulatory filing or victim disclosure lands.
- Attack vector
- Ransomware· thegentlemen
- Threat actor
- ThegentlemenExternalFinancial
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.