GLOBALMalwareFinancial ServicesFinanceRansomwareQilinRansom DemandedActor NamedData Leak ThreatenedData PublishedHigh
Metro-ILA Funds
bd_d37e318e837d47ad · schema v1 · pii pii-v1
Full breach record for Metro-ILA Funds →Threat-actor claim — not a regulatory filing
This row is a claim by the ransomware group Qilin on its public extortion blog. It has not been validated by the victim or any regulator. Treat attribution and counts as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.
Group activity: Financial ServicesDiscovered: 2026-04-29
Source: Ransomware.live
Post text · scraped from the leak site
N/A
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_388e0f66d7cdeb6eMassachusetts State AGfiled 2026-05-01(2d gap)Verified by operator
Source provenance
- Source URL
- https://www.ransomware.live/id/TWV0cm8tSUxBIEZ1bmRzQHFpbGlu
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 29, 2026
- Raw hash
- 4cff9e7497afbd4d3849fbe7032c3aafcbb1debb2623760909a989fc805c3094
Reporting entity
- Name
- qilin
Victim entity
- Name
- Metro-ILA Fundsnorm: metro ila funds
- Domain
- metro-ila.com
- Industry
- Financial Services
What this source establishes
- Source ceiling
- A leak-site claim can't tell us: discovery date · materiality · notification · affected count · confirmed data types · compliance clock. These stay blank until a regulatory filing or victim disclosure lands.
- Attack vector
- Ransomware· qilin
- Threat actor
- QilinExternalFinancial
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.