LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › MeridianLink fails to file with the SEC..so we do it for them + 24 hours to pay Listed by alphv Ransomware Group

HIGH severityUnverified claimHow we verify

MeridianLink fails to file with the SEC..so we do it for them + 24 hours to pay Listed by alphv Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·November 15, 2023
MeridianLink fails to file with the SEC..so we do it for them + 24 hours to pay Listed by alphv Ransomware Group

Reported November 15, 2023.

HIGH
Severity
November 15, 2023
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The MeridianLink fails to file with the SEC..so we do it for them + 24 hours to pay Listed by alphv Ransomware Group (reported November 15, 2023) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

On November 15, 2023, the ransomware group alphv listed MeridianLink on its leak site under a headline stating the company had failed to file with the SEC and giving a 24-hour payment window. The group claims to have stolen internal data in a ransomware attack. Public detail remains limited: the number of people affected is unknown, and no independent confirmation of the intrusion or the precise contents of any exfiltrated files has been provided in the available record.

The listing itself is an unverified claim by the threat actor. What is known so far is that alphv asserted it had taken internal files and publicly pressured the company over disclosure and payment. For customers, partners, and employees of a firm that sits inside lending and financial-technology workflows, even an unconfirmed claim of internal-file theft raises practical questions about what may have been exposed and what steps to take next.

Inside the incident

According to the reported summary, MeridianLink appeared on the alphv ransomware leak site on or around November 15, 2023. The group's own headline framed the listing as a substitute SEC filing and imposed a short payment deadline. The only data description given is that internal files were allegedly exfiltrated in a ransomware attack; the group claims to have stolen internal data.

No public figure has been released for the volume of data, the number of systems involved, or the initial access method. Timing of the underlying intrusion, beyond the November 15, 2023 listing date, is undisclosed. Scale—how many individuals or records might be implicated—is likewise unknown. The available facts do not confirm whether a ransom was paid, whether negotiations occurred, or whether any data was later published by the group. The incident is therefore documented primarily through the actor's leak-site claim rather than through a detailed victim disclosure in the record provided.

Inside alphv

alphv, also widely known in public reporting as BlackCat, is a ransomware operation that has functioned as a ransomware-as-a-service enterprise. Affiliates typically gain access to victim networks, exfiltrate data, deploy encryption, and then use a dedicated leak site to name organizations and threaten release of stolen material if payment demands are not met. The group has been associated with double-extortion tactics: encryption paired with the threat of data publication.

Public reporting over several years has linked alphv/BlackCat to attacks across multiple sectors, often with customized ransomware variants written in modern languages and with an emphasis on pressuring victims through regulatory and reputational angles—exactly the tone reflected in the MeridianLink listing headline that referenced an SEC filing. The group's leak-site posts are claims made by the actors themselves; they are not independent verification that every asserted detail is accurate. In this case, the facts state only that alphv listed MeridianLink and claimed theft of internal data, with a 24-hour payment framing.

Who is MeridianLink?

MeridianLink is a technology company that provides software platforms used by financial institutions, lenders, and related service providers. Its products commonly support loan origination, deposit account opening, mortgage workflows, and other consumer- and business-lending processes. Organizations of this type sit between banks, credit unions, and the customers those institutions serve; they routinely process or store sensitive operational and customer-related information as part of normal business.

A breach claim against such a firm is consequential because the company operates inside regulated financial workflows. Even when the precise scope of an incident is unconfirmed, the sector context means that internal files could, in principle, touch proprietary business data, configuration details, or information connected to lending customers. The available facts do not establish that any particular customer population was affected; they establish only that a prominent ransomware group publicly claimed exfiltration of internal files.

What data was at risk

The facts name the exposed material only as internal files exfiltrated in a ransomware attack. No inventory of file types, no record counts, and no categories such as names, Social Security numbers, account numbers, or credentials appear in the provided record. Exact contents therefore remain unconfirmed.

Organizations that supply lending and financial-technology platforms typically hold a mix of proprietary source or configuration data, internal business documents, employee information, and, depending on architecture and customer contracts, data related to loan applicants or account holders. That is the general profile of the sector—not a description of what alphv actually took in this case. Because the group’s claim is limited to “internal data” and “internal files,” any assertion about specific personal or financial data fields would be speculative and is not supported here.

What's at stake

For individuals, the real-world risk depends entirely on whether personal or financial information was among the internal files the group claims to have stolen—something the public record does not confirm. If such data were present, possible downstream issues could include targeted phishing that references lending or account activity, attempts to open new credit, or social-engineering attacks that exploit knowledge of an existing financial relationship. If the files were purely operational or corporate, the direct risk to consumers would be lower, though business partners could still face secondary exposure through shared systems or credentials.

For MeridianLink, the stakes include regulatory scrutiny, contractual obligations to financial-institution customers, potential notification duties, and reputational damage from a public ransomware listing—regardless of whether every detail of the actor’s claim is later substantiated. The unknown number of people affected and the lack of a detailed data inventory leave both the company and any potentially impacted parties without a clear perimeter for response. Until more verified information appears, the prudent posture is to treat the alphv claim as a serious allegation requiring monitoring rather than as a fully mapped breach.

Were you affected?

Public detail does not identify specific individuals or customer lists. If you have a relationship with MeridianLink or with a lender that uses its platforms, the following steps are reasonable first measures:

Because the scale and exact data types remain undisclosed, these steps are precautionary. Continue to watch for any official notice from MeridianLink or from institutions that use its services; such notices, if issued, will carry more specific guidance than a threat-actor listing alone can provide.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyMeridianLink security record
88/100
DoxxScan™ · Low doxx risk
B 83Good record

1 reported incident on record.

See MeridianLink’s full breach history →
RelatedMore incidents at MeridianLink

More recent breaches

Erbilbil Bilgisayar (You have 72 hours) Listed by alphv Ransomware GroupDecember 29, 2023Tipalti claimed as a victim - but we'll extort Roblox and Twitch, two of their affected cl Listed by alphv Ransomware GroupDecember 3, 2023Autonomous Flight - @autonomousfly Listed by alphv Ransomware GroupNovember 19, 20234set.es Listed by alphv Ransomware GroupNovember 14, 2023

Latest breaches

Read GalaxyWarden’s full analysis of the MeridianLink fails to file with the SEC..so we do it for them + 24 hours to pay Listed by alphv Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by alphv — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram