LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › The DGCX Listed by ransomhouse Ransomware Group

HIGH severityUnverified claimHow we verify

The DGCX Listed by ransomhouse Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·February 7, 2023
The DGCX Listed by ransomhouse Ransomware Group

Reported February 7, 2023.

HIGH
Severity
February 7, 2023
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

The The DGCX Listed by ransomhouse Ransomware Group (reported February 7, 2023) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

On 7 February 2023, the Dubai Gold & Commodities Exchange, known as The DGCX, was listed by the ransomware group ransomhouse. Public reporting states that internal files were exfiltrated in a ransomware attack. The number of people affected remains unknown, and further operational detail about timing, method, and full scope has not been disclosed in the available record.

A listing on a ransomware group’s leak site is a claim by that group, not an independent confirmation of every asserted detail. Even so, the appearance of a major regional commodities exchange in such a context raises clear questions for counterparties, staff, and anyone whose information may have been held in internal systems.

What happened

According to the breach record, The DGCX was listed by ransomhouse on or about 7 February 2023. The record describes internal files as having been exfiltrated in a ransomware attack. It does not publish a confirmed count of affected individuals, a precise attack timeline, technical indicators of compromise, or a full inventory of systems involved. Those elements are undisclosed in the material provided.

Ransomware incidents of this type commonly involve unauthorized access, theft of data, and pressure to pay through the threat of publication. Beyond the statement that internal files were taken and that the organisation appeared on the group’s listing, public detail specific to this case is limited. No dollar figures, file counts, or negotiated outcomes are stated in the facts.

Inside ransomhouse

Ransomhouse is a known ransomware operation that has appeared in public reporting as using double-extortion tactics: encrypting systems or holding access while also exfiltrating data, then threatening to publish material on a leak site if demands are not met. Groups in this category typically advertise victims on dedicated sites, sometimes with sample files, to increase pressure. Their activity has been tracked across multiple sectors and geographies in open-source security reporting.

For this incident, the available facts establish only that The DGCX was listed and that internal files were described as exfiltrated. Any broader claims the group may have made about volume, sensitivity, or specific contents of the haul are not independently verified in the record and should be treated as the group’s assertions rather than confirmed findings.

About The DGCX

The Dubai Gold & Commodities Exchange (DGCX) is described in the source material as the region’s first commodity derivatives exchange, having commenced trading in November 2005. Dubai has long served as an international hub for physical trade in gold and other commodities; the exchange was established as a logical extension of that role and has grown into a leading derivatives venue in the Middle East.

Organisations of this kind sit at the intersection of financial markets, clearing, membership onboarding, and regulatory reporting. They typically maintain records on members, traders, staff, counterparties, and operational processes. A breach affecting internal files at such an institution can therefore touch commercial, personal, and market-sensitive information even when the exact inventory remains unconfirmed.

The information in question

The facts name the exposed material as internal files exfiltrated in a ransomware attack. No further breakdown—such as customer lists, identity documents, financial account numbers, or specific document categories—is provided. The number of people affected is listed as unknown.

Exchanges and similar market infrastructure bodies ordinarily hold membership and onboarding data, communications, internal operational documents, and records tied to trading and compliance. Whether any of those categories were among the files taken in this case is unconfirmed. Readers should not assume a particular data type may have been exposed solely because it is common in the sector; only the general description of internal files is stated.

Why it matters

When internal files leave an organisation under ransomware conditions, the practical risks include misuse of commercial information, targeted phishing that references real internal details, and longer-term exposure if material is later published or resold. For individuals whose data may have been present—employees, members, or contacts—the concerns are identity misuse, credential stuffing if passwords or recovery data appeared in any files, and social-engineering attempts that sound authentic because they draw on genuine context.

For the exchange itself, consequences can include operational disruption, regulatory scrutiny, loss of counterparty confidence, and the cost of investigation and remediation. None of these outcomes is asserted here as having already occurred in full; they are the ordinary stakes when a financial-market institution is named in a ransomware listing and internal files are reported taken. The absence of a published headcount does not remove the need for caution among people connected to the organisation.

What to do if you're exposed

If you have a relationship with The DGCX—as staff, member, counterparty, or service provider—treat the incident as a prompt to tighten basic hygiene. Change passwords on related accounts, enable multi-factor authentication where available, and watch for unexpected messages that reference the exchange or internal processes. Monitor financial and identity accounts for unusual activity and consider a credit or fraud alert if you believe sensitive personal data could have been involved. Keep records of any suspicious contact.

Because the exact contents of the exfiltrated files remain unconfirmed, a measured response is more useful than panic. You can also run a free exposure scan of your email address to check whether your information has already surfaced in known breach datasets, and then prioritise remediation for any confirmed hits.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyThe DGCX security record
88/100
DoxxScan™ · Low doxx risk
B 83Good record

1 reported incident on record.

See The DGCX’s full breach history →

More recent breaches

Banco Promerica de la República Dominicana Listed by ransomhouse Ransomware GroupDecember 8, 2023Hbl Cpas, P.C. Listed by ransomhouse Ransomware GroupNovember 25, 2023ALPS Ltd Listed by ransomhouse Ransomware GroupNovember 4, 2023First Financial Security Listed by ransomhouse Ransomware GroupOctober 19, 2023

Latest breaches

Read GalaxyWarden’s full analysis of the The DGCX Listed by ransomhouse Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by ransomhouse — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram