International Busines Service Listed by crypto24 Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
International Busines Service was listed by the crypto24 ransomware group on April 08, 2025, after internal files were exfiltrated in a ransomware attack affecting an undisclosed number of people. Individuals who may have had data with the organization should review any notices from International Busines Service and consider protective steps such as monitoring accounts and changing passwords.
International Busines Service has been listed by the ransomware group crypto24 as a victim of a data breach, according to a report dated April 08, 2025. Public details remain limited: the number of people affected is unknown, and the group claims that internal files were exfiltrated in a ransomware attack. The reported summary of exposed material includes identity cards (front and back images and PDFs) for about 3,000 people, along with HR reports and pay documents. This listing is an unverified claim by the group rather than a confirmed disclosure by the organisation itself, yet it raises clear questions about the security of personal and employment-related records held by a business-services firm.
For individuals whose data may be involved, the practical concern is straightforward. Identity documents and payroll information can be misused for fraud or further targeting. Until more is confirmed, the incident stands as a claim of ransomware-driven theft of internal files, with the precise scale and method still undisclosed.
Inside the incident
What is known so far comes from the listing of International Busines Service by crypto24 on or around April 08, 2025. The group asserts that internal files were exfiltrated during a ransomware attack. No public confirmation has established the exact date of intrusion, the initial access method, or whether systems were encrypted in addition to the claimed data theft. The number of people affected remains unknown. The only concrete description available is the reported summary: identity cards showing front and back sides for about 3,000 people (in image and PDF formats), HR reports, and pay documents. Beyond that summary, further technical details such as file volumes, specific systems compromised, or any ransom demand have not been disclosed in the available record.
Because the information originates from a threat-actor leak-site claim, it should be treated as an assertion rather than independently verified fact. Organisations in this position sometimes later confirm or dispute such listings; at present no such confirmation or denial appears in the public facts provided.
The group behind it: crypto24
crypto24 is a ransomware operation that has appeared in public reporting as a group that combines encryption of victim systems with data exfiltration, a tactic commonly called double extortion. Like other ransomware crews, it typically posts victim names on a dedicated leak site and threatens to release stolen files if a ransom is not paid. Public knowledge of the group indicates it has targeted organisations across various sectors, using standard ransomware techniques such as initial access via compromised credentials or vulnerabilities, followed by lateral movement and data staging before encryption. Specific claims made by crypto24 about any single victim, including International Busines Service, remain the group’s own assertions and are not independently verified unless the victim organisation confirms them.
No additional statements from crypto24 about this particular incident—beyond the listing itself and the summary of identity cards, HR reports and pay documents—are recorded in the available facts. The group’s broader pattern is well-documented in open sources, but those patterns do not prove the details of any one case.
About International Busines Service
International Busines Service operates in the business-services sector. Organisations of this type typically provide administrative, human-resources, payroll, consulting or support functions to other companies. As a result they commonly hold employee identity documents, personnel files, salary records, contracts and other internal operational data. A breach involving such material can affect not only the firm’s own staff but also clients or contractors whose records are processed through the service.
Public background on the company itself is sparse in the given facts; the name appears as listed by crypto24. In general, firms handling identity and payroll data are attractive targets because the information has direct value for identity fraud and financial crime. The consequential nature of a breach here stems from that concentration of sensitive personal and employment records rather than from any established finding of negligence.
The information in question
According to the reported summary associated with the crypto24 listing, the material claimed to have been taken includes identity cards (front and back, in image and PDF form) for about 3,000 people, HR reports, and pay documents. The broader description given is simply “internal files exfiltrated in a ransomware attack.” Exact contents beyond that summary remain unconfirmed. Organisations that manage human-resources and payroll functions routinely store government-issued identity documents, tax identifiers, bank details for salary payments, performance records and employment contracts. Whether any of those additional categories were present in the claimed exfiltration has not been stated.
Because the number of people affected is listed as unknown and the data types are drawn from a threat-actor claim, it is not possible to assert with certainty which specific records, if any, have been exposed. The figures and file types given should be understood as the group’s description rather than verified inventory.
Why it matters
Identity cards containing front and back images can be used to create forged documents or to open fraudulent accounts. HR reports and pay documents often contain names, addresses, salary figures, tax identifiers and banking information—data that enables targeted phishing, tax fraud or unauthorised financial transactions. Even if the full set of files is never published, the mere possession of such material by criminals creates ongoing risk for the individuals named in it.
For the organisation, the incident carries operational and reputational consequences: potential regulatory scrutiny, the cost of investigation and notification, and the need to support affected people. Because the listing is still only a claim, the organisation may still be assessing the accuracy and scope of the alleged theft. In concrete terms, people whose identity or payroll data appear in the claimed files face elevated risk of identity theft and social-engineering attacks for months or years afterward.
Were you affected?
If you have ever worked with or through International Busines Service, or if you supplied identity documents or payroll information to a firm that uses its services, treat the possibility of exposure seriously. Monitor bank and credit accounts for unexpected activity, place fraud alerts with credit bureaus where available, and be cautious of unsolicited emails or calls that reference employment or identity details. Change passwords on any accounts that reused credentials linked to work email. Keep records of any suspicious contacts.
Readers can also run a free exposure scan of their email address to check whether that address has already appeared in known breach data sets. Such a scan does not prove or disprove involvement in this specific incident, but it provides a practical starting point for personal risk assessment while official details remain limited.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Yource Bulgaria & Greece Listed by crypto24 Ransomware GroupSOUBEIRAN CHOBET S.R.L. Listed by crypto24 Ransomware GroupMochtar Karuwin Komar: Indonesian law firm - MKK Listed by crypto24 Ransomware GroupEstudio O'Farrell Listed by crypto24 Ransomware GroupLatest breaches
Publicly posted by crypto24 — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.