LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Cadorim Listed by killsec Ransomware Group

HIGH severityUnverified claimHow we verify

Cadorim Listed by killsec Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·September 22, 2025
Cadorim Listed by killsec Ransomware Group

Reported September 22, 2025.

HIGH
Severity
September 22, 2025
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Cadorim was listed by the killsec ransomware group on September 22, 2025, after internal files were exfiltrated in an attack whose timing has not been established. Anyone connected to the organization should review their records and take appropriate protective steps if they may have been affected.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Ransomware groups continue to shape the modern threat landscape by combining data theft with public pressure, listing organisations on dedicated leak sites to force negotiations. These incidents rarely arrive with full transparency, leaving affected parties and the public to work from limited disclosures while assessing real-world exposure. Against that backdrop, the listing of Cadorim by the killsec ransomware group on 22 September 2025 fits a familiar pattern of claimed intrusion and data exfiltration whose precise scale remains unclear.

Public reporting indicates that Cadorim appeared on killsec’s leak site, with the group asserting it had stolen internal files during a ransomware attack. No independent confirmation of the intrusion or the volume of material taken has been released, and the number of people potentially affected is unknown. The episode matters because even unverified claims of internal-file theft can expose operational details and personal information that organisations of this type routinely handle, creating lasting risk for customers and staff alike.

What happened

On 22 September 2025, Cadorim was listed on the killsec ransomware leak site. According to the group’s own statement, internal files were exfiltrated as part of a ransomware attack. The listing itself constitutes the primary public record of the incident. No further technical details—such as the initial access vector, the duration of the intrusion, the exact volume of data taken, or any ransom demand—have been disclosed in available reporting. The number of individuals whose information may have been involved remains unknown. At present the claim rests solely on killsec’s assertion; independent verification has not been published.

Inside killsec

Killsec is a ransomware operation that has been active in the double-extortion model for several years. Like many contemporary groups, it typically gains access to a network, encrypts systems where possible, and simultaneously copies data before posting the victim’s name on a dedicated leak site. The public listing serves both as leverage and as a signal to other potential targets. Killsec has previously claimed responsibility for attacks against organisations across multiple sectors, often releasing sample files or full archives when negotiations stall. Its tactics align with established ransomware practices: opportunistic initial access, data theft, and public shaming rather than purely technical sophistication. In this case the group claims to have stolen internal data from Cadorim; that assertion has not been independently corroborated beyond the leak-site entry itself.

About Cadorim

Cadorim operates in the financial-services sector, providing money-transfer and remittance services that connect customers with recipients, frequently across international corridors. Companies of this kind maintain customer identity records, transaction histories, account credentials, and internal operational documents necessary for compliance and day-to-day business. Because remittance platforms sit at the intersection of personal finance and cross-border payments, a breach can affect both individual users and the organisation’s ability to meet regulatory obligations. The listing of such an entity therefore carries weight beyond a generic corporate compromise: it touches data that people rely on for everyday financial activity and that regulators expect to be protected.

The information in question

Public facts state only that internal files were exfiltrated. No inventory of specific data types—such as customer names, identity documents, transaction records, employee details, or proprietary business documents—has been released. Organisations operating money-transfer services typically hold precisely these categories of information, yet it remains unconfirmed whether any of them appear in the material killsec claims to possess. Until a more detailed disclosure or independent analysis emerges, the exact contents of the stolen files stay unknown. Readers should treat any subsequent claims of particular data categories as unverified unless corroborated by Cadorim or a trusted third party.

What's at stake

For individuals whose information may have been among the internal files, the practical risks include identity misuse, targeted phishing that references real transaction details, and longer-term fraud attempts that exploit knowledge of financial habits. Even partial internal documents can reveal enough about account structures or verification processes to make social-engineering attacks more convincing. For Cadorim itself the consequences include potential regulatory scrutiny, loss of customer confidence, and the operational cost of investigating and remediating the claimed intrusion. Because the number of people affected is unknown and the data types remain undisclosed, the full scope of exposure cannot yet be quantified; the uncertainty itself prolongs the period during which both the organisation and its users must remain vigilant.

If your data was in this claimed breach

If you have used Cadorim’s services, treat the possibility of exposure seriously even while details stay limited. Begin by changing any passwords associated with the platform and enabling multi-factor authentication where available. Monitor bank and remittance accounts for unexpected activity, and be sceptical of unsolicited messages that reference recent transfers or request personal verification. Consider placing fraud alerts with credit-reporting agencies if you reside in a jurisdiction that offers them. Finally, you can run a free exposure scan of your email address to check whether your information has already appeared in known breach data sets; such a scan provides an early indication of wider circulation and helps prioritise further protective steps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyCadorim security record
84/100
DoxxScan™ · Low doxx risk
B- 76Above-average record

1 reported incident on record.

See Cadorim’s full breach history →

More recent breaches

playroll Listed by killsec Ransomware GroupDecember 9, 2025caryanams Listed by killsec Ransomware GroupDecember 9, 2025KillSec 4.0 Listed by killsec Ransomware GroupOctober 4, 2025Fractalite Listed by killsec Ransomware GroupSeptember 22, 2025

Latest breaches

Read GalaxyWarden’s full analysis of the Cadorim Listed by killsec Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by killsec — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram