550madison.com Listed by qilin Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The Olayan Group’s 550madison.com domain has been listed by the Qilin ransomware group, with internal files reported exfiltrated. The listing was disclosed on 12 June 2025; an undisclosed number of individuals may be affected, and anyone connected to the organisation is advised to check for unusual activity and follow official guidance on credential changes and monitoring.
Ransomware groups continue to target large private enterprises and the assets they manage, using leak-site postings as leverage after claiming to have stolen internal data. In this environment, a listing that appears on a known ransomware site can signal both operational disruption and potential exposure of sensitive material, even when independent confirmation remains limited.
On 12 June 2025, the domain 550madison.com was listed by the qilin ransomware group in connection with The Olayan Group. Public reporting states that internal files were exfiltrated in a ransomware attack and that the group claims all data of the company will be available for download on 23 June 2025. The number of people affected is unknown, and further technical detail has not been disclosed.
Inside the incident
According to the available record, the incident centers on a listing of 550madison.com by the qilin ransomware group, reported on 12 June 2025. The Olayan Group is identified as the organization involved; 550 Madison is described as an architectural landmark in New York City managed by the group. The reported summary indicates that internal files were exfiltrated in a ransomware attack and that the group claims all data of this company will be available for download on 23 June 2025. No confirmed count of affected individuals has been published. The precise method of initial access, the volume of data taken, and any ransom demand or negotiation status remain undisclosed in the public facts. The listing itself constitutes a claim by the threat actor rather than an independently verified confirmation of full compromise.
Inside qilin
qilin is a ransomware operation that has operated as a ransomware-as-a-service model, enabling affiliates to deploy its encryptors and share proceeds. Public reporting on the group consistently describes a double-extortion approach: data is stolen before systems are encrypted, after which the group pressures victims by threatening to publish the material on a dedicated leak site if payment is not made. The group has previously listed organizations across multiple sectors and geographies, using timed release announcements to increase pressure. In this case, the leak-site listing of 550madison.com and the stated download date of 23 June 2025 should be treated as claims made by the group. No additional statements attributed specifically to this victim beyond those claims appear in the provided facts.
About The Olayan Group
The Olayan Group is a major private multinational enterprise with long-standing investment and holding activities. Organizations of this type typically oversee real-estate assets, corporate investments, and related operational entities. 550 Madison, an architectural landmark in New York City managed by the group, falls within that portfolio. A breach affecting such an organization is consequential because it may touch internal business records, tenant or client information associated with managed properties, and operational data used to run large commercial assets. Even when the exact scope is unconfirmed, the combination of a high-profile physical asset and a private investment group raises the potential impact on both corporate continuity and any individuals whose information appears in internal files.
The information in question
The facts name the exposed material only as internal files exfiltrated in a ransomware attack. Exact data types, file counts, and whether personal information of employees, tenants, or clients is included have not been disclosed. Organizations that manage landmark commercial properties and large investment portfolios commonly hold employee records, lease and tenant documentation, financial and contractual materials, vendor data, and internal correspondence. Because the public record does not confirm which of these categories, if any, were taken, the precise contents remain unconfirmed. Readers should treat any later appearance of specific documents as requiring independent verification rather than accepting the threat actor’s claims at face value.
What's at stake
For individuals whose details may appear in internal files, the practical risks include unwanted contact, phishing that references genuine business relationships, and longer-term identity or financial misuse if personal identifiers are present. For the organization, stakes include operational disruption, potential regulatory or contractual obligations if personal data is involved, reputational pressure from a public listing, and the cost of investigation and remediation. Because the number of people affected is unknown and the exact data types are not confirmed, the scale of these risks cannot yet be quantified from public sources alone.
- Unknown number of people potentially affected
- Claimed exfiltration of internal files with a stated publication date of 23 June 2025
- Unconfirmed presence of personal, tenant, or financial records
- Pressure on both the managed property’s operations and the parent group’s broader activities
Were you affected?
If you have a past or present relationship with The Olayan Group, 550 Madison, or related entities—as an employee, tenant, vendor, or client—monitor accounts and communications for unusual activity. Enable multi-factor authentication where available, treat unexpected messages that reference the organization with caution, and consider placing fraud alerts with credit bureaus if you believe personal identifiers could have been involved. Because public detail on this incident is limited, a free exposure scan of your email address against known breach data sets can help you check whether your information has already appeared in other documented incidents and decide on next steps.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Air Conditioning Florida & Mrdsllc & RTE Stucco & MR Drywall Services Listed by qilin Ransomware GroupGeorgia Dermatology & Skin Cancer Center Listed by qilin Ransomware GroupShore Gardens Rehabilitation & Nursing Center Listed by qilin Ransomware GroupSW/WC Service Cooperative Listed by qilin Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the 550madison.com Listed by qilin Ransomware Group →
Publicly posted by qilin — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.