LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › globacap.com Listed by apt73 Ransomware Group

HIGH severityUnverified claimHow we verify

globacap.com Listed by apt73 Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·August 21, 2024
globacap.com Listed by apt73 Ransomware Group

Reported August 21, 2024.

HIGH
Severity
August 21, 2024
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The globacap.com Listed by apt73 Ransomware Group (reported August 21, 2024) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

On 21 August 2024, the ransomware group known as apt73 listed globacap.com among the organisations whose systems it claims to have compromised. Public detail remains limited: the number of people affected is unknown, and the only description of the material involved is that internal files were allegedly exfiltrated. For anyone whose personal or professional information may sit inside those files—investors, clients, employees or counterparties—the practical stakes are immediate. Unauthorised access to internal records can expose financial details, identity data and correspondence that, once outside the organisation’s control, can be used for fraud, targeted phishing or further intrusion.

Because the listing itself is a claim made by the group rather than an independently verified disclosure, the full scope and confirmation of the incident are still unconfirmed. What is known is enough to warrant attention from those who have dealt with the firm.

Inside the incident

According to the public listing dated 21 August 2024, apt73 asserts that it conducted a ransomware attack against globacap.com and exfiltrated internal files. No further technical detail has been released: the precise date of intrusion, the initial access method, the volume of data taken, or whether encryption was also deployed remain undisclosed. The number of individuals whose information may be contained in the files is likewise unknown. The group’s leak-site entry constitutes an unverified claim; no independent confirmation of the breach’s success or of the data’s subsequent publication has been supplied in the available record.

In the absence of an official statement from the organisation detailing containment steps or forensic findings, the public picture rests solely on the group’s assertion that internal files left the network. Timing beyond the report date of 21 August 2024 is not provided.

Inside apt73

apt73 is a ransomware operation that has appeared in public reporting as a group practising double-extortion tactics: encrypting systems while simultaneously copying data and threatening to publish it if a ransom is not paid. Like many contemporary ransomware crews, it maintains a dedicated leak site on which it lists claimed victims, often posting samples or full archives once a deadline expires. Public analyses of the group’s activity describe typical initial-access methods used across the ransomware ecosystem—phishing, exploitation of unpatched remote-access services, or compromised credentials—followed by lateral movement, privilege escalation and data staging before encryption or exfiltration. Prior listings attributed to apt73 have involved organisations in finance, professional services and technology, though each claim must be treated separately and none of those earlier incidents automatically state the details of the globacap.com listing.

The group’s public communications are limited to the leak-site posts themselves; no additional statements specifically addressing this victim beyond the listing have been recorded in the facts available here. Attribution therefore rests on the group’s own claim.

globacap.com and its sector

Globacap operates as a private-markets platform designed to digitise and streamline the execution of investment transactions, reducing manual workflow for issuers, investors and intermediaries. Firms of this type sit at the intersection of fintech and capital markets: they handle onboarding documentation, investor identity records, transaction histories, share registers and communications that support private placements and secondary trading. Because the platform is built to compress administrative processes, it necessarily processes and stores sensitive commercial and personal data belonging to high-net-worth individuals, family offices, fund managers and corporate clients.

A breach affecting such an organisation is consequential precisely because the data it holds is both concentrated and high-value. Private-market participants expect confidentiality around deal terms, ownership structures and personal identifiers; any unauthorised disclosure can undermine trust in the platform and create secondary risks for every party whose information was stored there. The sector’s regulatory environment—anti-money-laundering checks, know-your-customer obligations and data-protection rules—further raises the stakes for both the firm and those whose records it maintains.

The information in question

The only data type named in the available facts is “internal files” said to have been exfiltrated during the ransomware attack. No inventory of file names, categories or volumes has been published, and the exact contents remain unconfirmed. Organisations operating private-markets platforms typically hold investor onboarding packs, passport or identity scans, bank-account details, transaction ledgers, shareholder registers, internal emails and commercial contracts. Whether any or all of those categories were among the files claimed by apt73 is not established by the public record. Readers should therefore treat any assumption about specific personal data as speculative until further disclosure occurs.

What's at stake

For individuals whose information may be inside the exfiltrated files, the concrete risks include identity fraud, unauthorised financial transactions, and highly targeted social-engineering attacks that reference genuine deal or account details. Even partial records—names linked to investment amounts or email addresses tied to internal correspondence—can be weaponised. For the organisation itself, the stakes include potential regulatory scrutiny, contractual liability to clients, reputational damage among private-market participants, and the operational cost of investigation and remediation. Because the number of people affected is unknown, the scale of these risks cannot yet be quantified; the uncertainty itself prolongs exposure for anyone who has interacted with the platform.

Secondary effects can also arise if the files contain credentials or system documentation that enable further intrusion into related networks. Until the organisation or independent investigators provide a clearer picture, those possibilities remain open.

What to do if you're exposed

If you have used globacap.com services, supplied identity documents, or conducted transactions through the platform, treat the possibility of exposure seriously even while confirmation is pending. Monitor bank and investment accounts for unexpected activity, enable multi-factor authentication wherever available, and be alert to phishing messages that reference private-market deals or request urgent verification. Consider placing fraud alerts with credit-reference agencies if you reside in a jurisdiction that offers them. Change any passwords that may have been reused across related services. Finally, you can run a free exposure scan of your email address to check whether that address has already appeared in known breach data sets; doing so provides an early indication of whether your information has circulated more widely.

Keep records of any suspicious contact and report confirmed fraud to the relevant authorities. Further official updates from the organisation, if issued, should be followed carefully so that protective steps can be adjusted as new facts emerge.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

Companyglobacap.com security record
88/100
DoxxScan™ · Low doxx risk
B 83Good record

1 reported incident on record.

See globacap.com’s full breach history →

More recent breaches

hl.co.uk Listed by apt73 Ransomware GroupApril 27, 2026federalbank.co.in (PART1) Listed by apt73 Ransomware GroupDecember 24, 2024linebank.co.id Listed by apt73 Ransomware GroupDecember 23, 2024federalbank.co.in Listed by apt73 Ransomware GroupDecember 20, 2024

Latest breaches

Read GalaxyWarden’s full analysis of the globacap.com Listed by apt73 Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by apt73 — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram