LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Kick Listed by mogilevich Ransomware Group

HIGH severityUnverified claimHow we verify

Kick Listed by mogilevich Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·March 1, 2024
Kick Listed by mogilevich Ransomware Group

Reported March 1, 2024.

HIGH
Severity
March 1, 2024
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The Kick Listed by mogilevich Ransomware Group (reported March 1, 2024) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

On March 1, 2024, the ransomware group known as mogilevich listed Kick, a video livestreaming platform, on its leak site. The group claimed it had successfully breached Kick’s systems, exfiltrated internal files totaling 75GB, and was offering the data for sale with a deadline of March 10, 2024. Public detail remains limited: the number of people affected is unknown, and independent confirmation of the breach has not been established beyond the group’s listing.

The claim matters because Kick hosts streamers, users, and affiliate relationships whose personal and operational data, if exposed, could create lasting privacy and security risks. What follows is a factual account of what is known, the actor involved, the sector context, and practical steps for anyone who may be affected.

What happened

According to the listing published by mogilevich, the group stated it had breached Kick’s systems and removed internal files. The post categorized the victim as video livestreaming and asserted that the compromised material included streamers/users data, affiliate program information, and logs. The claimed volume was 75GB. The group further announced that the data was also for sale and set a deadline of 3.10.24, inviting employees of the company or prospective buyers to contact them.

No independent verification of the intrusion method, exact date of access, or full scope has been made public in the available record. The number of individuals whose information may have been involved remains unknown. The listing itself constitutes an unverified claim by the threat actor; organizations in this position sometimes negotiate, sometimes dispute the claims, and sometimes confirm limited impact later. At the time of the report, those further details were not disclosed.

Inside mogilevich

Mogilevich is a ransomware operation that has appeared in public reporting as a group that combines encryption of victim systems with data theft—commonly called double extortion. Like other actors in this category, it typically publishes victim names on a dedicated leak site, posts samples or descriptions of stolen material, and threatens full release or sale if a ransom is not paid by a stated deadline. The name references a well-known organized-crime figure, a branding choice common among certain ransomware crews seeking notoriety.

Public documentation of the group’s broader activity shows a pattern of targeting organizations across multiple sectors, exfiltrating files before or during encryption, and monetizing the data either through ransom demands or secondary sale. Specific technical indicators, toolkits, or confirmed prior victims beyond general industry reporting are not required to understand the present claim; what matters here is that the group’s listing of Kick follows the standard public playbook of asserting a successful breach, naming data categories, stating a volume, and advertising the material for purchase. No additional statements by mogilevich about Kick beyond the March 1 listing are part of the factual record used for this account.

Kick and its sector

Kick is a video livestreaming service that allows creators to broadcast live content—primarily gaming, conversation, and entertainment—to audiences who watch, chat, and sometimes subscribe or tip. Platforms of this type sit at the intersection of social media, content creation, and digital commerce. They typically maintain accounts for streamers and viewers, payment or affiliate relationships, chat and moderation logs, and internal operational files needed to run the service.

A breach affecting such a platform is consequential because the user base often includes both high-profile creators and large numbers of ordinary viewers. Affiliate and partner programs can contain financial or contractual details. Logs may capture activity patterns, IP-related information, or moderation records. Even when the precise contents of a claimed theft remain unconfirmed, the sector’s reliance on trust, identity, and continuous online presence means that any credible claim of data exposure raises immediate questions about account security, privacy, and potential secondary misuse of the material.

What was likely exposed

The mogilevich listing named the following categories as compromised. These remain claims by the group rather than independently verified inventories:

Exact field-level contents—such as whether email addresses, passwords, payment tokens, private messages, or other identifiers were included—have not been disclosed in the public record. Organizations in the livestreaming sector commonly hold account credentials or recovery data, profile information, streaming analytics, payout or affiliate records, and system or application logs. Because the precise files taken in this incident are unconfirmed, it is not possible to state with certainty which of those typical holdings were present in the 75GB set. The group’s assertion that the data is for sale further indicates an intent to monetize whatever was obtained, but does not itself prove the completeness or accuracy of the claimed categories.

What's at stake

For individuals whose information may have been among the exfiltrated files, the concrete risks include targeted phishing that references their Kick activity, credential stuffing if passwords or recovery details were present, and unwanted contact or doxxing if personal identifiers appear in user or streamer records. Affiliate-related data could expose financial or contractual relationships. Logs, depending on their content, might reveal IP addresses, device details, or behavioral patterns useful for further social engineering.

For Kick itself, the stakes involve operational disruption, potential regulatory scrutiny depending on jurisdiction and data types, loss of creator and viewer trust, and the ongoing burden of determining whether the claim is accurate and, if so, notifying affected parties. Because the number of people affected remains unknown and the full contents unconfirmed, the scale of harm cannot yet be quantified. The existence of a public sale offer, however, means that any data that was taken could circulate beyond the original actor, extending the window of risk.

If your data was in this claimed breach

If you maintain an account on Kick as a streamer, viewer, or affiliate participant, treat the claim as a prompt for caution rather than confirmed personal exposure. Change your Kick password and enable multi-factor authentication if available. Use a unique password that does not appear on other services. Monitor email and financial accounts for unexpected messages that reference Kick or livestreaming activity. Be skeptical of unsolicited offers to “help recover” data or of links claiming to show the stolen files.

Because the exact population affected is unknown, a practical next step is to check whether your email address has already appeared in other known breach datasets. Free exposure-scan tools can search public breach corpora for your address and report matches without requiring you to pay or to supply unnecessary personal detail. Remain alert for follow-on reporting from Kick or independent researchers that may clarify the scope; until then, the prudent course is to harden accounts and treat any unexpected contact related to this incident with caution.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyKick security record
88/100
DoxxScan™ · Low doxx risk
B 83Good record

1 reported incident on record.

See Kick’s full breach history →

More recent breaches

DJI Company Listed by mogilevich Ransomware GroupMarch 1, 2024EpicGames Listed by mogilevich Ransomware GroupFebruary 27, 2024BAZAARVOICE.COM Listed by mogilevich Ransomware GroupFebruary 26, 2024Shein Listed by mogilevich Ransomware GroupMarch 1, 2024

Latest breaches

Read GalaxyWarden’s full analysis of the Kick Listed by mogilevich Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by mogilevich — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram