DUC App: Global Money Movement, Sim... Listed by killsec Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
DUC App disclosed on 23 October 2025 that internal files had been exfiltrated during a ransomware attack by the killsec group. Individuals should check whether their data may be involved and take protective steps if necessary.
Ransomware groups continue to target financial technology platforms that handle cross-border payments, cryptocurrency, and personal identity data, exploiting the high value of such records for extortion. On 23 October 2025 the killsec ransomware group listed DUC App on its leak site, claiming to have exfiltrated internal files during a ransomware attack. The number of people affected remains unknown, yet the listing alone raises concrete questions for users of a service that processes global money movement and identity verification.
Public detail on the incident is limited to the group’s claim and a brief description of the platform. No independent confirmation of the breach’s scale, method or success has been released, leaving affected individuals and the organisation itself to assess risk on incomplete information.
Breaking down the breach
According to the listing reported on 23 October 2025, killsec claims to have conducted a ransomware attack against DUC App that resulted in the exfiltration of internal files. The group has not published further technical indicators, timelines or ransom demands in the material available. The number of people affected is listed as unknown. No statement from DUC App confirming or denying the claim has been included in the public record of this incident. As with many ransomware listings, the assertion originates solely from the threat actor’s leak site and should be treated as an unverified claim until corroborated.
Inside killsec
Killsec is a ransomware operation that follows the now-common double-extortion model: encrypting systems while simultaneously stealing data and threatening to publish it if payment is not made. The group maintains a dedicated leak site where it posts victim names, sample files and, in some cases, larger data dumps. Public reporting over recent years has associated killsec with attacks on organisations across multiple sectors, typically using phishing or compromised credentials as initial access vectors before deploying ransomware. The group’s listings are promotional claims intended to pressure victims; they do not constitute independent verification that a breach occurred or that the volume of data matches what is advertised. In the present case, killsec’s only stated action is the listing of DUC App and the assertion that internal files were taken.
About DUC App
DUC App is described as a financial technology platform that enables individuals and businesses to manage global payments and currency exchange. Its services include instant transfers, international mobile top-ups, cryptocurrency transactions and API integrations for e-commerce, available via web, iOS and Android applications. Organisations of this type routinely collect and store customer identity documents, payment credentials, transaction records and wallet information in order to comply with anti-money-laundering rules and to facilitate transfers. A successful breach of such a platform can therefore expose both financial and personally identifiable data on a scale that affects users across multiple jurisdictions. The consequential nature of the incident stems from the sensitivity of the data typically held rather than from any confirmed volume of records.
The information in question
The killsec listing states that internal files were exfiltrated. The accompanying description asserts that the data includes, but is not limited to, clients’ home addresses, phone numbers, transaction histories, email addresses, public and private crypto address keys, verified documents, passports and IDs. These categories are presented as part of the group’s claim; independent confirmation of the exact contents or the completeness of the set has not been provided. Organisations operating global payment and cryptocurrency services commonly retain precisely these categories of information for regulatory and operational purposes, yet the precise files taken in this incident remain unconfirmed beyond the threat actor’s statement.
What's at stake
If the claimed data are accurate, individuals face risks of identity theft, account takeover and targeted phishing that leverage real transaction histories and identity documents. Private cryptocurrency keys, if present and usable, could enable direct theft of digital assets. Home addresses and phone numbers increase the possibility of physical or social-engineering attacks. For DUC App the stakes include regulatory scrutiny under data-protection and financial-services rules, potential loss of customer trust, and the operational cost of investigation and remediation. Because the number of affected people is unknown and the claim remains unverified, both users and the organisation must treat the exposure as a credible possibility rather than an established fact.
Were you affected?
Anyone who has used DUC App for payments, currency exchange or cryptocurrency transactions should monitor account activity, enable multi-factor authentication where available, and consider rotating passwords and API keys. Review bank and wallet statements for unauthorised transfers. If identity documents were submitted, place fraud alerts with credit bureaus and remain alert for phishing that references the platform. Readers can also run a free exposure scan of their email address to check whether their information has already appeared in known breach data sets. Until DUC App or independent investigators publish further detail, these steps remain the most practical immediate response.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Rainwalk Technology Listed by killsec Ransomware GroupDUC App: Global Money Movement, Simplified Listed by killsec Ransomware Groupscreenate Listed by killsec Ransomware GroupJ AND S Electrical And Lighting Sup... Listed by killsec Ransomware GroupLatest breaches
Publicly posted by killsec — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.