LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › fractal.id Listed by stormous Ransomware Group

HIGH severityUnverified claimHow we verify

fractal.id Listed by stormous Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·July 14, 2024
fractal.id Listed by stormous Ransomware Group

Reported July 14, 2024.

HIGH
Severity
July 14, 2024
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The fractal.id Listed by stormous Ransomware Group (reported July 14, 2024) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
HIGH severityUnverified claim
Contact / identity PII exposed.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

On July 14, 2024, the ransomware group stormous listed fractal.id on its leak site, claiming to have carried out a ransomware attack that involved the exfiltration of internal files. Public detail remains limited to the group's own statements; independent confirmation of the intrusion, its full scope, or the precise status of any ransom demand has not been disclosed. The listing matters because fractal.id operates as a digital identity and KYC provider, handling sensitive personal records for clients in regulated sectors.

According to the group's post, the material taken includes data from the company's KYC system and other systems, with the actors asserting that more than 300,000 users linked to Fractal ID clients were involved. No official statement from fractal.id quantifying affected individuals or confirming the breach has been included in the available record.

Inside the incident

The sole public marker of the incident is the stormous listing dated July 14, 2024, under the headline that fractal.id had been listed by the group. The actors describe a ransomware attack in which internal files were allegedly exfiltrated, stating that the full leak of fractal.id is available and directing attention to web.fractal.id. They claim to have extracted over 10 GB of data—later referenced as exceeding 12 GB—from the KYC system and some of its other systems. The group further asserts that the breach includes more than 300,000 users linked to Fractal ID clients in its KYC service, and that the material encompasses personal photos, bank statements, proof of address, and ETH/BTC addresses. The post ends with a note that a report will be published soon about the company's status regarding data protection. No independent verification of these figures, the attack vector, the encryption status of systems, or any negotiation has been reported. The number of people affected remains listed as unknown outside the group's claims.

Inside stormous

Stormous is a ransomware operation that follows the now-standard double-extortion model: encrypting systems while simultaneously copying data and threatening public release if payment is not made. Like many such groups, it maintains a leak site where it posts victim names, sample files, and countdown timers to pressure organisations. Public reporting on stormous has documented its use of common initial-access methods such as phishing or exploitation of exposed services, followed by lateral movement and data staging before encryption. The group has previously listed a range of corporate and institutional targets, typically framing each post with claims of large data volumes and sensitive content. In the present case the listing itself constitutes an unverified claim; nothing in the available facts states that stormous successfully encrypted fractal.id systems or that the stated data volumes were in fact taken.

Who is fractal.id?

Fractal.id provides digital identity and know-your-customer (KYC) verification services, primarily serving platforms in the cryptocurrency, blockchain and fintech sectors that must meet anti-money-laundering and customer-identification rules. Organisations of this type collect and store government-issued identity documents, facial photographs, proof-of-address records, and sometimes financial or wallet-related information so that their clients can onboard users in a compliant manner. Because the service sits at the centre of identity assurance for multiple downstream platforms, a compromise can expose not only the provider's own staff data but also the personal records of hundreds of thousands of end users who never interacted directly with fractal.id. The consequential nature of such a breach therefore stems from the concentration of high-value identity material in a single KYC repository.

The information in question

The facts name the exposed material only as "internal files exfiltrated in ransomware attack." All further detail originates from the stormous listing itself. The group claims the haul exceeds 10 GB (referenced as 12 GB) and includes personal photos, bank statements, proof of address, and ETH/BTC addresses belonging to more than 300,000 users of Fractal ID clients. These specific categories remain unconfirmed by any independent source. Organisations that operate KYC platforms typically hold precisely the kinds of documents the actors describe—scanned identity cards, selfies used for biometric matching, utility bills, and cryptocurrency wallet addresses—yet the exact contents of any archive allegedly taken from fractal.id have not been verified publicly. Readers should therefore treat the listed data types as assertions rather than established fact.

The real-world impact

If the claimed data were indeed exfiltrated, affected individuals face elevated risks of identity theft, targeted phishing, and financial fraud. Personal photographs and proof-of-address documents can be used to open fraudulent accounts or to craft convincing social-engineering attacks; bank statements and cryptocurrency addresses add financial targeting opportunities. For fractal.id the consequences include potential regulatory scrutiny under data-protection regimes, contractual liability to client platforms, and reputational damage that may erode trust among both institutional customers and end users. Because the number of people affected is still recorded as unknown outside the group's statements, the precise scale of individual harm cannot yet be measured. Organisations in the identity-verification sector often face heightened notification obligations once a breach is confirmed, which can extend the period of uncertainty for those whose records may have been involved.

Were you affected?

Anyone who has completed KYC checks through a service that relies on fractal.id should monitor financial accounts and credit reports for unusual activity and consider placing fraud alerts where available. Change passwords on related platforms, enable multi-factor authentication, and remain alert to phishing messages that reference identity documents or cryptocurrency wallets. Because public confirmation of the exact data set is still lacking, the most practical immediate step is to check whether your email address has already appeared in known breach corpora. Readers can run a free exposure scan of their email to determine whether their information has surfaced in previously documented incidents, providing an early indicator while further details about this listing continue to emerge.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

Companyfractal.id security record
88/100
DoxxScan™ · Low doxx risk
B 83Good record

1 reported incident on record.

See fractal.id’s full breach history →

More recent breaches

or-technology.com Listed by stormous Ransomware GroupMay 3, 2026AOSense Listed by stormous Ransomware GroupOctober 14, 2024aosense.com Listed by stormous Ransomware GroupOctober 5, 2024asobostudio Listed by stormous Ransomware GroupSeptember 30, 2024

Latest breaches

Read GalaxyWarden’s full analysis of the fractal.id Listed by stormous Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by stormous — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram