LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Argentem Creek Partners (investment firm) Listed by N0n Ransomware Group

HIGH severityUnverified claimHow we verify

Argentem Creek Partners (investment firm) Listed by N0n Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·September 18, 2026
Argentem Creek Partners (investment firm) Listed by N0n Ransomware Group

Reported September 18, 2026.

HIGH
Severity
September 18, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Argentem Creek Partners was listed on September 18, 2026 by the ransomware group N0n, which claims to hold data from an undisclosed number of people. Individuals who may have had dealings with the firm should check whether their information is at risk and consider protective steps such as monitoring accounts and enabling two-factor authentication.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Ransomware groups continue to pressure companies by posting them on leak sites and threatening to release material unless a settlement is reached. Those postings are accusations, not verified findings: they appear without independent confirmation from the named firm, regulators, or established breach trackers, and they can be incomplete, recycled, or wrong.

On a listing dated September 18, 2026, the group known as N0n has named Argentem Creek Partners, a United States investment-management and private-credit firm. Public detail on the claim is limited. The company has not publicly confirmed the claim as of writing. What follows treats the leak-site entry as an unverified claim and explains what such a listing does and does not establish for people who may have ties to the firm.

What is being claimed

According to the listing, N0n has placed Argentem Creek Partners on its leak site and describes the firm as investment management / private credit in the United States. The group claims that, if no settlement is reached, it will publish material it characterizes as full corporate network evidence. The listing’s own wording refers to more than 2.5 million connection records, a complete internal systems map said to cover Active Directory, SharePoint, MSP tooling, and office-security integrations, tax-season document flows of the firm and its investor document delivery platform, and an assertion that corporate connectivity remains severed until settlement.

The number of people affected is unknown. Data types are not disclosed in the sense of a confirmed inventory of personal or client files; the description above is the group’s marketing language on the listing, not an audited catalog. Timing of any intrusion, technical method, and whether any files actually left the environment are undisclosed in public reporting tied to this record. None of these points has been confirmed by the company in the material provided for this article.

Who is N0n?

N0n is known publicly as a ransomware and extortion-style actor that operates in the pattern common to many leak-site crews: encrypt or disrupt systems, exfiltrate data or claim to have done so, then list the victim and threaten publication to force payment. Groups in this category often post partial samples, screenshots, or high-level descriptions of internal infrastructure to increase pressure. Their posts are strategic communications aimed at negotiation, not neutral disclosure.

Well-documented public reporting on such actors emphasizes that listings can exaggerate volume, recycle older material, or misattribute access. For this specific naming of Argentem Creek Partners, only the claims on the September 18, 2026 listing are in scope: the group claims possession of extensive network and document-related material and frames non-payment as leading to publication. Independent verification of those claims is not part of the available record.

Who is Argentem Creek Partners?

Argentem Creek Partners is identified in the listing as an investment firm focused on investment management and private credit in the United States. Firms in that sector typically raise and deploy capital, maintain relationships with limited partners and borrowers, and handle sensitive commercial, legal, and financial documentation. They often operate investor portals, document-delivery platforms, and internal collaboration systems that sit alongside core identity and network infrastructure.

A leak-site listing against such an organization matters because of the sensitivity of the sector, not because the listing itself proves a breach. Counterparties, employees, and service providers may reasonably want to understand what is alleged and what remains unproven. A listing does not establish that systems were compromised, that data left the firm, or that any particular person’s information is involved; it establishes only that a named extortion group has chosen to make a public claim.

The information in question

The facts for this incident state that data types named as exposed are not disclosed in a confirmed sense. The listing’s text—connection records, an internal systems map spanning directory services, collaboration tools, managed-service tooling, and office-security integrations, plus tax-season and investor document-delivery flows—is the attacker’s description of what it says it will publish. That description should not be read as a verified inventory.

If files of the kind private-credit and investment firms commonly hold were ever taken, organizations in this sector typically retain items such as investor and counterparty contact details, subscription and capital-call related documents, internal credit memos, tax and K-1 style materials in season, contracts, and credentials or configuration data tied to corporate IT. Whether any of that is implicated here is unconfirmed. People affected, if any, are unknown. Readers should treat every specific category as conditional on verification that has not been provided in the public facts for this article.

The real-world impact

For individuals and entities connected to an investment firm, the practical risks—if a listing’s claims were later substantiated—would center on misuse of business and personal identifiers, targeted phishing that references real internal systems or document workflows, and exposure of commercial terms that were meant to stay confidential. Connection logs and systems maps, if genuine, can help attackers or opportunists craft more convincing follow-on social engineering. Tax-season and investor-delivery materials, if involved, can raise identity-theft and fraud concerns for people whose documents appear in those flows.

For the organization, an extortion listing can create operational, legal, and reputational pressure regardless of whether the underlying claim is accurate. Severed connectivity, if it occurred as the group asserts, would disrupt normal work; that assertion remains the group’s claim. What a leak-site entry does establish is public naming and a threat narrative. What it does not establish is confirmed theft, a validated file list, confirmed victim counts, or any finding about the firm’s security design, detection, or response. Those conclusions would require evidence beyond an unverified listing.

What to do now

Because this matter is an unconfirmed claim, steps should stay conditional: act if you have a real relationship with the firm and you see signs that your information may be involved, not because a leak site alone proves your data is out.

You can also run a free exposure scan of your email to check whether your address has already appeared in known breach datasets unrelated to this claim. That kind of check does not confirm or deny the N0n listing about Argentem Creek Partners; it only helps you see whether your email is already circulating in broader breach corpora and whether further hardening of your accounts is overdue. Treat the September 18, 2026 listing as an allegation until the company or another authoritative source confirms otherwise.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

SourceLeak-site claim data adapted from RansomLook.io, used under CC BY 4.0.

CompanyArgentem Creek Partners security record
84/100
DoxxScan™ · Low doxx risk
B- 76Above-average record

1 reported incident on record.

See Argentem Creek Partners’s full breach history →

More recent breaches

PayPal support operations (Transcom WorldWide) Listed by N0n Ransomware GroupSeptember 18, 2026Vietnamese betting operator (GC789 network / Boundless TE) Listed by N0n Ransomware GroupSeptember 18, 2026BeLi Teacher / FSC education centers (AWS) Listed by N0n Ransomware GroupSeptember 18, 2026AstraZeneca Türkiye Listed by N0n Ransomware GroupSeptember 18, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the Argentem Creek Partners (investment firm) Listed by N0n Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by n0n — unverified claim, pending independent verification. Leak-site claim data adapted from RansomLook.io, used under CC BY 4.0.

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram