h*i**c*.c*m.my Listed by devman Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
h*i**c*.c*m.my was listed by the devman ransomware group on 28 October 2025 after internal files were exfiltrated. Individuals who have used the service should verify whether their data was exposed and take protective steps.
People whose personal or work-related information may sit inside the systems of h*i**c*.c*m.my now face a period of uncertainty. On 28 October 2025 the organisation appeared on a ransomware group’s leak site, with claims that internal files had been taken. When the precise contents and the number of individuals involved remain unknown, the practical risk is that ordinary contact details, account records or internal documents could later be misused for fraud, phishing or identity-related harm.
Public reporting so far is limited to the listing itself and a short summary of the claimed demand. That scarcity of confirmed detail makes it harder for anyone who has dealt with the organisation to know whether their own data is among the material said to have been removed.
Inside the incident
According to the available record, h*i**c*.c*m.my was listed by the ransomware group known as devman on 28 October 2025. The listing characterises the event as a ransomware attack in which internal files were allegedly exfiltrated. The reported summary attached to the listing states a ransom demand of 500k and a data volume of 60 gb. No further technical description of the intrusion method, the exact date of access, or the systems involved has been made public. The number of people whose information may be affected is recorded as unknown.
Because the only source for these figures is the group’s own claim, independent verification of the volume of data, the ransom amount, or the completeness of the exfiltration has not been established in the public record. The incident is therefore known principally through the leak-site entry rather than through confirmed forensic disclosure.
The group behind it: devman
Devman is a ransomware operation that has appeared in public threat reporting as a group that encrypts systems and simultaneously claims to steal data for leverage. Like many contemporary ransomware actors, it typically posts victim names on a dedicated leak site and threatens to publish or sell the material if payment is not made. Public analyses of the group’s activity describe the use of double-extortion tactics—encryption combined with data theft—and the publication of sample files or volume claims to pressure organisations.
In this case the group claims that h*i**c*.c*m.my is a victim and that 60 gb of internal files were taken, with a ransom figure of 500k attached to the listing. Those assertions remain claims originating from the group itself; they have not been independently confirmed in the material available for this report. Devman’s prior public activity follows the same pattern of listing organisations and advertising stolen data volumes, but no additional statements specific to this organisation beyond the listing details have been recorded here.
Who is h*i**c*.c*m.my?
h*i**c*.c*m.my is a commercial organisation registered under the Malaysian .com.my domain. Organisations of this type typically operate in the private sector and maintain customer, supplier or employee records as part of ordinary business. Exact public details about the company’s size, sector specialisation or the precise nature of its services are not expanded in the breach record itself.
A breach involving such an entity is consequential because commercial organisations routinely hold contact information, contractual documents, financial correspondence and internal operational files. Even when the organisation is not a household name, the data it stores can still identify individuals and support further social-engineering or fraud attempts once it leaves controlled systems.
The information in question
The facts state that internal files were exfiltrated in a ransomware attack. No more granular inventory of data types—such as names, identity numbers, financial records or medical information—has been disclosed. The reported summary mentions only a 60 gb volume and the ransom figure.
Organisations of this kind commonly hold employee records, customer contact lists, invoices, contracts and internal communications. Whether any of those categories are present in the claimed 60 gb set remains unconfirmed. Readers should therefore treat the exact contents as unknown rather than assume any particular category of personal data has been verified as exposed.
Why it matters
For individuals, the principal risk is that any personal or contact information contained in the internal files could later be used to craft convincing phishing messages, attempt account takeovers, or support identity-related fraud. Because the number of people affected is unknown and the file contents are not itemised, it is impossible to rule out exposure for anyone who has interacted with the organisation.
For the organisation itself, the listing creates operational, legal and reputational pressure. Even if the ransom is not paid, the claimed existence of 60 gb of internal material outside its control can disrupt normal business, require notification obligations under applicable data-protection rules, and necessitate long-term monitoring for secondary misuse of the data. The absence of confirmed scale does not remove these practical consequences; it simply leaves both the organisation and potentially affected people without a clear inventory of what must be protected or monitored.
Were you affected?
If you have an account, membership, employment relationship or regular correspondence with h*i**c*.c*m.my, treat the possibility of exposure as real until more information appears. Change passwords on any related accounts, enable multi-factor authentication where available, and watch for unexpected messages that reference the organisation or request personal details. Monitor financial statements and credit activity for unusual behaviour.
You can also run a free exposure scan of your email address to check whether that address has already appeared in known breach data sets. Doing so provides one concrete data point while official confirmation about this specific incident remains limited.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
***-***tems.*** Listed by devman Ransomware Grouparko.no Listed by devman Ransomware Groupn*w*****.com Listed by devman Ransomware Groupm*tt**ca**r**.**.it Listed by devman Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the h*i**c*.c*m.my Listed by devman Ransomware Group →
Publicly posted by devman — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.