LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Coop57 Listed by incransom Ransomware Group

HIGH severity claimedUnverified claimHow we verify

Coop57 Listed by incransom Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·April 8, 2025
Coop57 Listed by incransom Ransomware Group

Reported April 8, 2025.

HIGH
Severity
April 8, 2025
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Coop57 was listed by the incransom ransomware group on April 08, 2025, after internal files were exfiltrated in a ransomware attack. Anyone associated with the organisation should check for updates and follow any guidance issued by Coop57.

Severity & verification
HIGH severity claimedUnverified claim
Exposes government-ID data.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

People who bank, invest, or work with ethical finance cooperatives may now face the practical risk that personal identity documents linked to their accounts or memberships have been taken by criminals. On 8 April 2025, the ransomware group incransom listed Coop57 on its leak site and claimed to have stolen more than 12,000 identity cards and passports belonging to citizens of various countries. The number of people affected remains unknown, and public detail about the full scope is limited, yet the claim alone raises immediate concerns for anyone whose records may sit in Coop57’s systems.

Because Coop57 operates as a financial instrument within the social and solidarity economy, the data it holds can include sensitive personal identifiers used for account opening, loans, or cooperative membership. If the group’s assertion is accurate, those documents could be used for fraud, identity theft, or further targeting. This article sets out only what is known from the public listing and established background, without speculation.

Inside the incident

According to the reported listing dated 8 April 2025, Coop57 was named by the incransom ransomware group as a victim of a ransomware attack in which internal files were exfiltrated. The group claims that over 12,000 IDs and passports of citizens of different countries were taken. No further technical details—such as the exact date of intrusion, the initial access method, the total volume of data, or confirmation of encryption—have been disclosed in the available record. The number of individuals affected is listed as unknown. Public information stops at the group’s claim of exfiltration of internal files and the specific assertion about identity documents; nothing else about the timeline, ransom demand, or recovery status has been confirmed.

Because the information originates from a ransomware leak-site listing, it must be treated as an unverified claim by the threat actor rather than an independently verified fact. Organisations in this position sometimes later confirm or dispute such claims; at present, no such confirmation appears in the provided facts.

Who is incransom?

incransom is a ransomware operation that follows the now-common double-extortion model: it encrypts systems and simultaneously steals data, then threatens to publish the stolen material on a dedicated leak site if a ransom is not paid. Like other groups of this type, it typically posts victim names, sample files, and sometimes volume claims to pressure organisations into negotiation. Public reporting on the group has documented its use of standard ransomware tooling and its practice of listing both large and mid-sized entities across multiple sectors. No additional claims made by incransom specifically about Coop57—beyond the listing itself and the assertion of more than 12,000 IDs and passports—are recorded in the facts available here. The group’s statements remain claims until corroborated by the organisation or independent investigation.

About Coop57

Coop57 describes itself as a financial instrument that forms part of the fair and solidarity finance system. Its stated mission is to provide options that meet the diverse financial needs of citizens and actors in the social economy. To that end it works within a network of microfinance organisations and federations, jointly developing strategies aimed at building a social and solidarity economy and creating alternative models of the economic cycle. In practical terms, such cooperatives typically handle member deposits, ethical loans, investment vehicles, and related administrative records for individuals and small social-economy enterprises.

Because the organisation sits at the intersection of personal finance and cooperative membership, a breach of its systems is consequential: it can expose not only transactional data but also the identity documents required for regulatory compliance and account verification. The social-economy sector often serves people who value transparency and ethical practice; any compromise of trust or personal data therefore carries both practical and reputational weight for the cooperative and its community.

What data was at risk

The facts name the exposed material as “internal files exfiltrated in ransomware attack.” The incransom listing further claims that over 12,000 IDs and passports of citizens of different countries were taken. No other data types are specified. Organisations of Coop57’s kind commonly hold identity documents, contact details, account information, loan or investment records, and membership files. Whether any of those additional categories were among the exfiltrated files remains unconfirmed. The exact contents of the stolen material, beyond the group’s claim regarding identity documents, are therefore undisclosed.

Why it matters

Identity documents such as national ID cards and passports are high-value items for criminals. They can be used to open fraudulent accounts, apply for credit, impersonate individuals in official processes, or combine with other leaked data to enable more convincing social-engineering attacks. For people whose documents may be among those claimed, the risk is concrete: potential financial loss, administrative burden of replacing documents, and the longer-term need to monitor credit and identity activity. For Coop57 itself, the incident—if the claims hold—raises operational, regulatory, and trust issues common to any financial cooperative that handles personal data. Because the number of people affected is unknown and the full data set is unconfirmed, the precise scale of harm cannot yet be measured; the practical stakes for those whose records are involved remain real regardless.

If your data was in this claimed breach

If you have held an account, membership, or other relationship with Coop57, treat the possibility of exposure seriously even while the full details stay limited. Monitor bank and credit statements for unfamiliar activity, consider placing fraud alerts with relevant credit agencies where available, and be alert to phishing attempts that reference the cooperative or request identity verification. Replace any physical identity documents only through official channels if you receive confirmation they were compromised. As a further practical step, you can run a free exposure scan of your email address to check whether that address or associated personal information has already appeared in known breach data sets. Stay attentive to any official statements Coop57 may issue; until then, the group’s claims remain the primary public source of information about this incident.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyCoop57 security record
87/100
DoxxScan™ · Low doxx risk
B 80Good record

1 reported incident on record.

See Coop57’s full breach history →

More recent breaches

3GH Informatica Integral Listed by incransom Ransomware GroupDecember 31, 2025Precise Benefits Group LLC Listed by incransom Ransomware GroupDecember 16, 2025PFMI Listed by incransom Ransomware GroupNovember 27, 2025Evolve Mortgage Services Listed by incransom Ransomware GroupOctober 30, 2025

Latest breaches

Read GalaxyWarden’s full analysis of the Coop57 Listed by incransom Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by incransom — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram