Mobidic Asset Management Listed by qilin Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
Mobidic Asset Management was listed by the qilin ransomware group on September 30, 2025, after internal files were exfiltrated in a ransomware attack. The number of individuals affected is undisclosed; anyone who had a relationship with the firm should verify their status and follow any official guidance issued by Mobidic.
On 30 September 2025, Mobidic Asset Management was listed by the ransomware group known as qilin. Public reporting states that internal files were exfiltrated in a ransomware attack. The number of people affected remains unknown, and further operational details of the incident have not been disclosed.
The listing itself is a claim published on the group’s leak site. What is confirmed so far is limited: the organisation has been named, the attack is described as involving ransomware with data theft, and the company is identified as a Korean asset-management firm that has traded on the country’s stock market since 2021 under its former name EX-DK Investment Korea, with reported capital of 6 billion won (approximately $4.2 million).
Inside the incident
According to the available record, Mobidic Asset Management appears on a qilin leak-site listing dated 30 September 2025. The accompanying summary characterises the event as a ransomware attack in which internal files were taken. No public confirmation has been issued regarding the precise date of intrusion, the initial access method, the volume of data removed, or whether systems were encrypted in addition to the claimed exfiltration.
The number of individuals whose information may have been involved is listed as unknown. No ransom demand figure, negotiation timeline, or independent verification of the stolen material has been released in the facts available. The listing refers to the firm as “KoreanLeak3 – another failure,” but that language is the group’s own characterisation and has not been independently corroborated.
Inside qilin
Qilin is a ransomware operation that has been active for several years and is widely documented as operating a ransomware-as-a-service model. Affiliates typically gain access to corporate networks, move laterally, exfiltrate data, and then deploy encryption while threatening to publish the stolen material if payment is not made. The group maintains a public leak site on which it posts victim names and, in some cases, sample files or full archives.
Public reporting on prior qilin activity shows a pattern of targeting mid-sized organisations across multiple sectors and geographies, often emphasising double-extortion tactics. Claims made on the leak site are assertions by the group; they do not automatically constitute verified proof that every listed organisation suffered the full scope of compromise described. In this instance, the only specific claim tied to Mobidic Asset Management is the listing itself and the statement that internal files were exfiltrated.
Mobidic Asset Management and its sector
Mobidic Asset Management is a South Korean firm that has operated on the national stock market since 2021, previously known as EX-DK Investment Korea. Publicly reported capital stands at roughly 6 billion won. Asset-management companies of this type typically oversee client portfolios, investment funds, and related financial products. They therefore hold or process sensitive commercial and personal information, including account details, transaction records, identity documents, and internal corporate files.
A breach affecting such an organisation raises concerns because financial-services data can be used for fraud, identity theft, or competitive intelligence. Even when the precise contents of any stolen archive remain unconfirmed, the sector’s regulatory and fiduciary responsibilities mean that any unauthorised access to internal systems carries potential consequences for clients, counterparties, and the firm’s own operations.
What was likely exposed
The facts state only that “internal files” were exfiltrated. No inventory of specific document types, databases, or personal-data categories has been published. Organisations in the asset-management sector commonly retain the following categories of material; whether any of these were among the files taken in this incident is unconfirmed:
- Client identity and contact records
- Account and transaction histories
- Internal financial reports and investment strategies
- Employee and contractor personnel files
- Contracts, correspondence, and operational documents
Until an official statement or independent analysis appears, the exact contents of the claimed archive remain unknown.
Why it matters
For individuals whose data may have been held by Mobidic Asset Management, the primary risks are financial fraud and identity misuse. Stolen account numbers, identification documents, or contact details can be sold or reused in phishing and social-engineering campaigns. Even if encryption was not applied, the mere removal of internal files can expose proprietary business information and create long-term compliance and reputational costs for the firm.
Because the scale of the incident and the precise data types remain undisclosed, the full extent of harm cannot yet be measured. Clients and counterparties have a legitimate interest in knowing whether their records were involved and what protective steps the organisation has taken. The absence of confirmed numbers does not eliminate the need for vigilance; it simply means that affected parties must rely on official updates and personal monitoring rather than on a complete public inventory.
If your data was in this claimed breach
If you have been a client, employee, or business partner of Mobidic Asset Management, treat the listing as a signal to act cautiously. Monitor bank and investment accounts for unexpected activity, enable multi-factor authentication wherever available, and be alert to unsolicited communications that reference the firm or request sensitive information. Consider placing fraud alerts with credit-reporting agencies if you hold accounts in jurisdictions that offer that service.
Readers can also run a free exposure scan of their email address to check whether that address has already appeared in known breach data sets. Keep records of any correspondence with the company and follow official guidance once it is issued. Public detail remains limited; further clarity will depend on statements from Mobidic Asset Management or independent investigators.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
EUM Asset Management Listed by qilin Ransomware GroupST Asset Management Co Listed by qilin Ransomware GroupOrum Asset management Listed by qilin Ransomware GroupDblock Asset Management Co Listed by qilin Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the Mobidic Asset Management Listed by qilin Ransomware Group →
Publicly posted by qilin — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.