London Capital Group(LCG) Listed by akira Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The London Capital Group(LCG) Listed by akira Ransomware Group (reported June 26, 2023) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
Ransomware groups continue to target financial services firms, using leak sites to pressure organisations and advertise stolen material. In late June 2023, the group known as akira listed London Capital Group (LCG), a global online financial trading platform and multi-asset broker, among its claimed victims. Public detail remains limited: the number of people affected is unknown, and independent confirmation of the intrusion has not been widely reported. What is known comes chiefly from the group's own leak-site posting, which asserts that internal files were taken and that client personal information would be published.
For clients and counterparties of a multi-asset broker, any credible claim of exfiltration raises practical questions about account security, identity exposure and the integrity of trading records. This article sets out the available facts, places the listing in context, and outlines steps individuals can take while the full scope stays unconfirmed.
What happened
On or around 26 June 2023, London Capital Group (LCG) appeared on the leak site associated with the akira ransomware group. The listing described an attack in which internal files were allegedly exfiltrated. The group's own statement claimed it had “studied this company from the inside,” asserted that the firm’s practices were “not very clean,” and said that data would be made available “soon,” including “detailed personal information about their clients” so that outsiders could “see the mechanics of these brokers with your own eyes.”
No public figure has been given for the volume of data, the number of affected individuals, or the precise date the intrusion began or ended. Method of initial access, dwell time, and whether encryption was also deployed have not been disclosed in the material available for this account. The listing itself constitutes a claim by the threat actor; it has not been independently verified in the facts provided here. As with many ransomware postings, the group’s statements mix operational assertions with commentary intended to increase pressure on the named organisation.
Who is akira?
Akira is a ransomware operation that emerged in public reporting in 2023 and has since been associated with double-extortion tactics: encrypting systems where possible while also stealing data and threatening to publish it if payment is not made. The group maintains a Tor-based leak site on which it names victims, posts samples or full archives, and sets deadlines. Public analyses of akira activity have described the use of compromised credentials, exploitation of exposed remote-access services, and rapid movement to data theft once inside a network. The group has targeted organisations across multiple sectors, including professional services, manufacturing and finance, often selecting mid-sized firms whose operations depend on continuous access to systems and client records.
Like other ransomware brands, akira’s leak-site entries are self-reported claims. Inclusion of a name does not by itself prove successful encryption or the full extent of any theft; it does, however, signal that the group wishes the organisation and its stakeholders to believe sensitive material is under its control. In the LCG listing, the group went beyond a bare announcement and added critical commentary about the broker’s practices, a rhetorical step sometimes used to heighten reputational pressure. No further technical indicators or ransom demands specific to this incident are contained in the facts at hand.
Who is London Capital Group(LCG)?
London Capital Group (LCG) is described in the available material as a global online financial trading platform and multi-asset broker. Firms of this type typically offer retail and professional clients access to foreign exchange, contracts for difference, commodities, indices and other instruments through web and mobile platforms. They hold customer identity and contact data, account and trading histories, payment and banking details used for deposits and withdrawals, and internal records covering compliance, risk and operations.
A breach affecting such an organisation is consequential because the data it holds can be directly monetised or abused: trading credentials and account identifiers may enable unauthorised activity, while personal and financial details support identity fraud or targeted social engineering. Even when the precise contents of any stolen archive remain unverified, the sector’s regulatory and reputational environment means that claims of client-data exposure attract scrutiny from customers, partners and, potentially, supervisors. The facts supplied for this incident do not state whether LCG has issued its own public confirmation or notification; they record only the akira listing and the group’s accompanying claims.
What data was at risk
The facts name the exposed material as “internal files exfiltrated in ransomware attack.” The akira posting further asserted that “detailed personal information about their clients will also be posted.” No inventory of file types, record counts, or specific data fields has been published in the material available here. People affected remain unknown.
Organisations in the multi-asset brokerage sector ordinarily maintain know-your-customer documentation, proof-of-identity and address records, email and telephone contacts, account numbers, transaction and position histories, and internal communications and operational documents. It is reasonable to expect that any substantial internal archive could contain a mixture of these categories. Because the exact contents have not been independently confirmed, it is not possible to state as fact which of these elements, if any, were present in the material akira claims to hold. Readers should treat the group’s description as an unverified assertion until corroborated by the organisation or by reliable third-party analysis.
What's at stake
For individuals whose information may have been involved, the concrete risks include phishing and social-engineering attempts that reference genuine account or personal details, attempts to reset or take over trading or email accounts, and longer-term identity-fraud exposure if government identifiers or financial account data were present. Even partial records—names, emails, phone numbers and account references—can be combined with other breach data to increase the credibility of scams.
For the organisation, the stakes include operational disruption if systems were encrypted, regulatory and contractual notification duties if personal data of clients or staff were confirmed stolen, potential loss of client confidence, and the cost of investigation, remediation and customer support. Because the scale and precise composition of the claimed exfiltration remain undisclosed, the full extent of these risks cannot yet be quantified. The absence of a confirmed headcount or data inventory does not eliminate the need for caution; it simply means responses must be proportionate to what is actually known.
If your data was in this claimed breach
If you have held an account or otherwise shared personal information with London Capital Group, treat the akira claim as a prompt to review your exposure rather than as proof that your records were taken. Change passwords on any related accounts, enable multi-factor authentication where available, and monitor account statements and credit reports for unfamiliar activity. Be alert to unsolicited messages that reference the firm or your trading history; verify any such contact through official channels rather than links or numbers supplied in the message itself.
You can also run a free exposure scan of your email address to check whether it has already appeared in known breach datasets. That step will not confirm or rule out involvement in this specific incident, but it can indicate whether your address is circulating more widely and help you prioritise further hardening of credentials and recovery options. Remain guided by official notices from the organisation or from relevant regulators as more verified information becomes available.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Venture General Agency Listed by akira Ransomware GroupOffutt Nord Listed by akira Ransomware GroupSchmidt Salzman & Moran, Ltd Listed by akira Ransomware GroupLCG company (URGENT!) Listed by akira Ransomware GroupLatest breaches
Publicly posted by akira — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.