https://heritagegrowth.com/ Listed by incransom Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Heritage Growth Partners was listed by the incransom ransomware group on September 14, 2025, indicating that internal files were exfiltrated in a ransomware attack. Individuals are advised to check whether their information was exposed and to monitor their accounts for any suspicious activity.
On September 14, 2025, the ransomware group known as incransom listed Heritage Growth Partners on its leak site, claiming the firm had suffered a ransomware attack in which internal files were exfiltrated. Public reporting identifies the organization as a private family investment office; the number of people affected remains unknown, and further operational details of the incident have not been disclosed.
Because investment offices routinely handle confidential financial and partnership information, any confirmed compromise of internal material carries potential consequences for the firm, its portfolio companies, and associated individuals. At present the listing itself constitutes the primary public claim.
Inside the incident
According to the available record, Heritage Growth Partners was named by incransom on September 14, 2025. The group asserts that internal files were taken during a ransomware attack. No public confirmation has been issued regarding the precise date of intrusion, the method of initial access, the volume of data removed, or whether encryption was also deployed. The number of individuals whose information may have been involved is listed as unknown. Beyond the claim of exfiltrated internal files, no further technical or forensic particulars have been released.
The group behind it: incransom
Incransom is a ransomware operation that has appeared in public threat reporting as employing double-extortion tactics: encrypting systems while also copying data and threatening to publish it if a ransom is not paid. Like other groups of this type, it maintains a leak site on which it posts victim names and, in some cases, samples of stolen material. The listing of Heritage Growth Partners is presented by the group as evidence of a successful intrusion; independent verification of that claim has not been supplied in the public record. Incransom’s prior activity follows patterns common to contemporary ransomware crews—targeting organizations that hold commercially sensitive or personal data and using the threat of disclosure as leverage. No statements attributed specifically to this victim beyond the listing itself appear in the facts available.
Heritage Growth Partners and its sector
Heritage Growth Partners was founded in 2014 as a private, family investment office focused on growth-equity investments made in collaboration with owner-managers. The firm describes a patient, flexible capital approach that includes strategic, financial, and operational support intended to foster long-term business growth. Its clients are primarily owner-managers seeking both capital and collaborative resources. Private investment offices of this kind sit within the broader private-equity and family-office sector, where confidential deal documents, financial projections, partnership agreements, and personal information of principals and portfolio-company executives are routinely maintained. A breach affecting such an organization can therefore touch both institutional and individual stakeholders whose commercial and personal interests are closely intertwined.
What data was at risk
The public record states only that internal files were exfiltrated. Exact data types, file counts, or categories of personal or financial information have not been disclosed. Organizations operating as family investment offices typically store materials such as investment memoranda, financial statements, correspondence with portfolio companies, personal contact details of principals, and related legal or tax documents. Whether any of those categories were among the files claimed by incransom remains unconfirmed. Until more precise inventories are released by the firm or by independent investigators, the precise contents of the exfiltrated material cannot be stated as fact.
Why it matters
For individuals connected to Heritage Growth Partners—whether principals, employees, or managers of portfolio companies—the primary risks center on the possible misuse of confidential business or personal information. Internal files could enable targeted social-engineering attempts, competitive intelligence gathering, or, if personal identifiers are present, identity-related fraud. For the firm itself, the incident raises questions of operational continuity, client trust, and potential regulatory or contractual notification duties, even though no public finding of negligence has been established. Because the scale of exposure is unknown, the practical impact ranges from limited internal disruption to broader reputational and financial consequences depending on what was actually taken and how it is subsequently used.
Were you affected?
If you have a professional or personal relationship with Heritage Growth Partners or any of its portfolio companies, monitor financial accounts and correspondence for unusual activity and consider placing fraud alerts with major credit bureaus where appropriate. Preserve any official notifications you receive from the firm. Readers can also run a free exposure scan of their email address to check whether that address has already appeared in known breach data sets; such a scan provides an additional, independent indicator of whether personal contact information has circulated. Further updates will depend on any additional disclosures the organization or investigators may choose to release.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
https://sibillacapital.com/ Listed by incransom Ransomware Grouphttps://daricon.com/ Listed by incransom Ransomware GroupPrecise Benefits Group LLC Listed by incransom Ransomware GroupPFMI Listed by incransom Ransomware GroupLatest breaches
Publicly posted by incransom — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.