villagecoin.com Listed by qilin Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
villagecoin.com has been listed by the Qilin ransomware group, with the breach disclosed on 1 July 2025. An undisclosed number of people may have been affected; check the status of your account and change your password if you have one.
Ransomware groups continue to target specialised retailers and dealers that handle customer records and commercial documents, using leak-site listings to pressure organisations after claimed data theft. In this landscape, smaller or niche businesses can face the same double-extortion tactics as larger firms, even when public details remain sparse.
On 1 July 2025, the ransomware group qilin listed villagecoin.com, also known as Village Coin Shop, claiming to have exfiltrated internal files in a ransomware attack. The number of people affected is unknown, and independent confirmation of the full scope has not been published. The listing matters because the business deals in numismatic products and mint bullion, categories that typically involve customer and transaction records whose exposure can create lasting practical risks for individuals and the firm itself.
What happened
Public reporting states that villagecoin.com was listed by the qilin ransomware group on 1 July 2025. According to the available summary, the group claims internal files were exfiltrated in a ransomware attack. Named elements associated with the listing include client lists and at least one illustrative file described as an invoice from SilverTowne (STLP) to the organisation. The precise timing of any intrusion, the technical method used, the volume of data taken, and whether systems were encrypted remain undisclosed. No confirmed figure for affected individuals has been released. The listing itself constitutes a claim by the group rather than independently verified proof of every asserted detail.
The group behind it: qilin
qilin is a ransomware operation that has been active in the public threat landscape for several years. Like many contemporary groups, it is widely documented as operating a ransomware-as-a-service model in which affiliates conduct intrusions and the core operators manage negotiation and leak-site infrastructure. Public reporting on the group consistently describes a double-extortion approach: data is stolen before or during encryption, and victims are threatened with publication if a ransom is not paid. qilin has previously listed organisations across multiple sectors on its leak site, using partial file samples or descriptions to demonstrate claimed access. In this case, the group claims villagecoin.com as a victim and asserts that internal files were taken; those assertions should be treated as the group’s unverified statements unless further confirmation appears. No additional specific claims by qilin about this particular victim beyond the listing and the named file types are provided in the available facts.
villagecoin.com and its sector
Village Coin Shop, operating as villagecoin.com, specialises in a wide variety of numismatic products and is recognised as a dealer of US Mint bullion and Royal Canadian Mint bullion. Businesses of this type sit at the intersection of retail, collectibles, and precious-metals trading. They commonly maintain customer contact details, purchase histories, shipping addresses, and commercial invoices with suppliers. Because bullion and rare-coin transactions can involve high-value items and identity verification for compliance or shipping, the sector routinely holds personal and financial-adjacent information. A breach affecting such a dealer is consequential precisely because the data, if real, can link real-world identities to valuable purchases and ongoing commercial relationships, creating opportunities for targeted fraud or social engineering that go beyond generic credential stuffing.
The information in question
The facts state that internal files were exfiltrated in the claimed ransomware attack. Explicitly named elements include client lists and a sample file described as an invoice from SilverTowne (STLP) to the organisation. Beyond these references, the exact contents of the full data set are not disclosed. Organisations in the numismatic and bullion-dealer sector typically hold customer names, contact details, order records, shipping information, and supplier invoices; some may also retain payment-related metadata or identity documents required for higher-value transactions. None of those additional categories can be confirmed as present in this incident. The public record therefore establishes only that client lists and at least one invoice-type document have been associated with the listing; everything else remains unconfirmed.
The real-world impact
For individuals whose details may appear in client lists, the primary risks are phishing, social-engineering calls, and targeted scams that reference genuine past purchases or shipping addresses. Fraudsters can use such information to appear more credible when requesting payment updates, account “verification,” or further personal data. For the organisation, the consequences include potential regulatory notification duties, customer-notification costs, reputational damage among collectors and bullion buyers, and the operational burden of investigating and containing any residual access. Because the number of people affected is unknown and the full data inventory is unconfirmed, the scale of these impacts cannot yet be quantified. Even limited client-list exposure can produce months of elevated fraud attempts against customers who previously bought coins or bullion through the shop.
If your data was in this claimed breach
If you have ever purchased from or supplied Village Coin Shop, treat the possibility of exposure seriously even while details remain limited. Monitor bank and card statements for unexpected activity, be sceptical of unsolicited messages that reference coin or bullion orders, and consider placing fraud alerts with credit bureaus if you provided identity documents for larger transactions. Change passwords on any accounts that reused credentials associated with the shop, and enable multi-factor authentication wherever available. Readers can also run a free exposure scan of their email address to check whether their information has already surfaced in known breach data sets, which provides an additional early-warning signal while official notifications, if any, are still pending.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Luminex Software Listed by qilin Ransomware GroupZ-Tronix Listed by qilin Ransomware GroupVeton Ai Listed by qilin Ransomware GroupTBC Consoles Listed by qilin Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the villagecoin.com Listed by qilin Ransomware Group →
Publicly posted by qilin — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.