LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Palmgold Management Sdn Bhd Listed by crypto24 Ransomware Group

HIGH severityUnverified claimHow we verify

Palmgold Management Sdn Bhd Listed by crypto24 Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·August 5, 2025
Palmgold Management Sdn Bhd Listed by crypto24 Ransomware Group

Reported August 5, 2025.

HIGH
Severity
August 5, 2025
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Palmgold Management Sdn Bhd has been listed by the crypto24 ransomware group after internal files were exfiltrated in an attack. The incident was disclosed on 5 August 2025, affecting an undisclosed number of individuals; anyone connected to the company should verify their status and take steps to secure their information.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

People whose personal details, membership records or financial information may sit inside Palmgold Management Sdn Bhd’s systems now face a concrete risk that those records have left the company’s control. On 5 August 2025 the ransomware group crypto24 publicly listed the organisation, claiming it had taken a large volume of internal data. The number of individuals affected remains unknown, and independent confirmation of the full scope has not been published, yet the claim alone is enough to put members, staff and partners on alert.

Because the listing describes both casino-member databases and credit-division files, anyone who has held a membership, placed bets, applied for credit or worked inside the company has reason to treat the incident as personally relevant until clearer facts emerge.

Inside the incident

Public reporting on 5 August 2025 stated that crypto24 had listed Palmgold Management Sdn Bhd on its leak site. The group asserted that it had conducted a ransomware attack and exfiltrated more than 500 GB of data from the company’s internal network. According to the same claim, the material came from both the Casino Division and the Credit Division and included operational databases, analytics dashboards, finance and HR documents, scanner-share contents from multiple branches, and various operational formulas. No independent verification of the volume, exact date of intrusion, or method of entry has been released. The number of people whose records may be involved is listed as unknown. Palmgold Management Sdn Bhd has not, in the material available, issued a detailed public technical account of the event.

Inside crypto24

Crypto24 is a ransomware operation that follows the now-familiar double-extortion model: it encrypts systems while simultaneously copying data, then threatens to publish the stolen material if a ransom is not paid. Groups of this type typically maintain dedicated leak sites where they post victim names, sample files and countdown timers. Their public statements are therefore claims rather than Reported Facts; the listing of Palmgold Management Sdn Bhd should be read in that light. Crypto24 has previously targeted organisations across several sectors, using standard ransomware tooling and data-exfiltration techniques that have been documented in open-source reporting. Nothing in the available record confirms that the group has released the Palmgold files, only that it claims to possess them.

Palmgold Management Sdn Bhd and its sector

Palmgold Management Sdn Bhd is a Malaysian company whose operations, according to the group’s own description of the stolen material, include a Casino Division and a Credit Division. Organisations of this kind typically manage membership programmes, gaming-floor systems, credit facilities, and the associated finance, human-resources and IT infrastructure. They therefore hold large volumes of personal and financial data belonging to members, employees and counterparties. A breach that reaches both casino and credit systems can expose records that are both commercially sensitive and personally identifiable, raising the stakes for anyone who has interacted with the company in those capacities.

What data was at risk

The only concrete description of the data comes from crypto24’s own claim. The group stated that it had taken more than 500 GB of “most sensitive and business-critical data,” specifically naming the full operational database of over 60 000 casino members (including personal information, jackpot and play history, betting patterns and machine configurations), Power BI analytics dashboards, confidential finance, HR and IT documents, complete scanner-share contents from branches identified as kmscan, toshibascan and fujiscan, and operational logic such as promotion formulas and game-specific rules. These details remain unconfirmed by independent sources. Organisations operating casinos and credit facilities ordinarily hold membership identifiers, contact details, transaction histories, credit assessments, employee records and internal financial reports; whether every category listed by the group was in fact copied cannot be verified from public information alone.

The real-world impact

For individuals, the practical risks include identity misuse, targeted phishing that references genuine play or credit history, and potential fraud against any linked financial accounts. Membership databases that contain betting patterns and personal identifiers can be used to craft highly convincing social-engineering attempts. For the organisation, the consequences may include regulatory scrutiny under Malaysian data-protection rules, loss of member trust, and the operational cost of investigating and remediating the incident. Because the exact contents and any subsequent publication remain unconfirmed, the full scale of harm cannot yet be measured; the prudent assumption is that sensitive records left the network and may reappear in criminal markets.

If your data was in this claimed breach

Anyone who has held a membership, credit facility or employment relationship with Palmgold Management Sdn Bhd should treat the claim seriously. Monitor bank and credit statements for unfamiliar activity, enable multi-factor authentication on email and financial accounts, and be sceptical of unsolicited messages that reference casino play or credit details. Consider placing fraud alerts with credit-reporting agencies where available. Readers can also run a free exposure scan of their email address to check whether that address has already appeared in known breach data sets; doing so provides an early indication of whether personal information is circulating more widely.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyPalmgold Management Sdn Bhd security record
87/100
DoxxScan™ · Low doxx risk
B 80Good record

1 reported incident on record.

See Palmgold Management Sdn Bhd’s full breach history →

More recent breaches

Bayu Buana Travel Listed by crypto24 Ransomware GroupOctober 27, 2025Bayu Buana Travel Service Listed by crypto24 Ransomware GroupOctober 20, 2025Tan Chong Motor Holdings Berhad Listed by crypto24 Ransomware GroupJuly 9, 2025Warisan TC Holdings Berhad Listed by crypto24 Ransomware GroupJuly 9, 2025

Latest breaches

Read GalaxyWarden’s full analysis of the Palmgold Management Sdn Bhd Listed by crypto24 Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by crypto24 — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram