Keepz Listed by killsec Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Keepz was listed by the killsec ransomware group on January 25, 2025, after internal files were exfiltrated in a ransomware attack affecting an undisclosed number of people. Individuals should check whether their data was exposed and take steps to secure their accounts.
Ransomware groups continue to single out payment and fintech firms because the data those companies handle can be converted quickly into fraud or further extortion. Against that backdrop, the listing of Keepz by the killsec ransomware group on 25 January 2025 is a reminder that even specialised digital-payment providers remain exposed. Public detail is limited: the number of people affected is unknown, and only the broad claim of “internal files” has been made. Still, any confirmed or claimed compromise at a payment platform warrants careful attention from customers, partners and the wider sector.
What is known so far comes almost entirely from the group’s own leak-site announcement. No independent confirmation of the intrusion method, the volume of data taken, or the precise timeline has been released by Keepz or by regulators. The incident therefore sits in the familiar grey zone of modern ransomware reporting—serious enough to note, yet still short of verified technical findings.
What happened
On 25 January 2025, the ransomware group killsec publicly listed Keepz on its leak site. According to the listing, the attackers claim to have conducted a ransomware attack that included the exfiltration of internal files. No further technical indicators—such as the initial access vector, the ransomware strain used, or any ransom demand—have been disclosed in the available record. The number of individuals or organisations whose data may have been involved remains unknown. Keepz itself has not, in the public material reviewed for this article, issued a detailed incident statement confirming or denying the claims. As a result, the core facts rest on the group’s assertion that internal files were taken during a ransomware operation.
The group behind it: killsec
killsec is a ransomware operation that has appeared repeatedly in public threat reporting since at least 2023. Like many contemporary groups, it typically follows a double-extortion model: encrypting systems while also stealing data and threatening to publish it if a ransom is not paid. The group maintains a leak site where it posts victim names, sample files and, in some cases, full archives. Its targets have ranged across manufacturing, professional services and technology firms; payment and fintech entities have also appeared among its claimed victims. killsec’s public communications are usually brief and formulaic, focusing on the volume of data allegedly stolen rather than on sophisticated technical claims. Because the listing of Keepz is itself only a claim by the group, it should be treated as unverified until independent evidence or an official confirmation emerges. Nothing in the present record indicates that killsec has released sample files specific to Keepz or has named particular data categories beyond “internal files.”
Keepz and its sector
Keepz is a digital-payment solution provider headquartered in Tbilisi, Georgia. Its flagship offering is a QR-based payment system that allows businesses to accept payments without traditional card terminals or mandatory end-user registration. In practical terms, the company sits at the intersection of merchant acquiring, mobile payments and small-business fintech. Organisations of this type routinely process transaction metadata, merchant account details, and sometimes limited personal or device identifiers associated with payers. Even when full card numbers are tokenised or never stored, the surrounding business records—contracts, settlement files, support tickets, internal communications—can still contain commercially sensitive or personally identifiable information. A breach at such a provider therefore carries consequences both for the merchants who rely on the service and for any individuals whose payment activity touches the platform. Georgia’s growing fintech sector has attracted regional and international attention; an incident involving one of its payment innovators underscores the broader pressure ransomware groups place on emerging digital-finance ecosystems.
What data was at risk
The only data category named in the available facts is “internal files exfiltrated in a ransomware attack.” No inventory of file types, no count of records, and no confirmation of customer or merchant data have been published. In the absence of those specifics it is not possible to state what was actually taken. Organisations that operate QR payment systems typically hold merchant onboarding documents, transaction logs, settlement reports, employee records and system configuration files. Any of those categories could fall under the umbrella of “internal files,” yet none can be asserted as fact for this incident. Readers should therefore treat the precise contents as unconfirmed. Until Keepz or an independent investigator releases a verified list, the safest assumption is that the scope remains unknown.
Why it matters
For individuals and small businesses that have used Keepz, the practical risks centre on secondary fraud and social-engineering attacks. Even limited internal documents can contain email addresses, phone numbers or transaction patterns that criminals later exploit in phishing or invoice-fraud schemes. Merchants may face operational disruption if payment processing is interrupted or if settlement data is altered. For Keepz itself, the listing creates reputational pressure and potential regulatory scrutiny under Georgian and, depending on customer location, European data-protection rules. Because the number of people affected is unknown, the scale of any downstream harm cannot yet be measured; the absence of that figure does not reduce the need for vigilance. In the wider threat landscape, the incident illustrates how ransomware groups continue to treat payment intermediaries as high-value targets whose data can be leveraged for both financial gain and public pressure.
If your data was in this claimed breach
If you are a merchant or individual who has used Keepz services, begin by monitoring bank and card statements for unfamiliar transactions and enable any available transaction alerts. Change passwords associated with the Keepz platform and with any linked email accounts, preferably using a password manager and multi-factor authentication. Be alert for unexpected emails or messages that reference recent payments or request urgent action; treat such contact as potential phishing until verified through official channels. Keepz has not published a list of affected parties, so there is no definitive way to know whether your information was among the claimed files. As a practical next step, you can run a free exposure scan of your email address against known breach datasets to see whether that address has already appeared in other incidents. Document any suspicious activity and report it to your bank and, if appropriate, to local cybercrime authorities. Remaining calm, methodical and sceptical of unsolicited contact remains the most effective immediate response while further details, if any, emerge.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Force Brokerage Listed by killsec Ransomware GroupSkyward Specialty Insurance Listed by killsec Ransomware Groupgrade results Listed by killsec Ransomware Groupdabafinance.com Listed by killsec Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the Keepz Listed by killsec Ransomware Group →
Publicly posted by killsec — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.