LeakNet Ransomware Group Claims Data Breach at SWAN General Limited
Riya5 min read

LeakNet Ransomware Group Claims Data Breach at SWAN General Limited

LeakNet ransomware group claims responsibility for a data breach at SWAN General Limited, Mauritius. Attackers allege theft of sensitive customer records, financial documents, and internal emails in an ongoing extortion attempt.

Share:

What we're tracking

The LeakNet ransomware group has claimed responsibility for a data breach at SWAN General Limited, a Mauritius-based insurance provider.

On the group's dark web leak portal, the attackers say they exfiltrated hundreds of gigabytes of sensitive data, including:

  • Customer identification documents (IDs, passports)
  • Insurance policy contracts and claims records
  • Financial documents and transaction logs
  • HR files and internal communications

Nobody has independently verified the dump yet, so treat the specifics with caution. But the claim fits a pattern I watch closely on my threat-intel desk: financial and insurance institutions keep getting picked off because they sit on enormous piles of personally identifiable information (PII) and sensitive business data.


The claim, in brief

Field Details
Date of Claim August 13, 2025
Threat Actor LeakNet ransomware group
Target Organization SWAN General Limited (Mauritius)
Alleged Data Theft Hundreds of GB of internal and customer data
Extortion Tactic Threat to leak stolen data unless ransom paid

The posting lines up with LeakNet's double extortion model, where data gets stolen before encryption and then used as leverage during ransom negotiations.


Who is LeakNet?

LeakNet is a newer group, but it's grown fast. We've tracked its activity since late 2024.

What sets them apart

  • Runs a "double extortion" playbook: encrypt, exfiltrate, then leak
  • Operates a darknet leak portal where it lists victims
  • Goes after sectors with high-value data: insurance, healthcare, manufacturing, banking

Where they've shown up (2024–2025)

  • Manufacturing targets in Asia
  • Healthcare providers in Europe
  • Banks and insurers in Africa

The throughline is money. LeakNet exposes sensitive records, then resells them in underground markets or recycles them into the next round of attacks.


Why this could hurt

If the SWAN General Limited claim holds up, the fallout could include:

  • Customer Exposure → Policyholder PII and ID documents are perfect fuel for identity theft and fraud
  • Regulatory Scrutiny → A possible investigation under the Mauritius Data Protection Act (GDPR-aligned)
  • Operational Disruption → Stolen data erodes trust and can knock operations sideways
  • Secondary Threats → Exposed data feeds phishing, social engineering, and insider attacks

That last point is the one defenders underrate. I've watched a single leaked dataset seed credential-stuffing and account-takeover waves months after the original breach went quiet.


Indicators of Compromise (IOCs)

⚠️ Note: These IOCs are based on past LeakNet campaigns—specific artifacts tied to SWAN General Limited have not been confirmed.

Malware Hashes

  • b37a3f93f9f5c9d3a9a1a2f0a2a8c933 – Ransomware loader (SHA-256)
  • c11f2a0a4b1a0a76bbf0d7d7f7ac445e – Credential harvester (SHA-256)

C2 Infrastructure (2025)

  • leaknet[.]onion – Darknet leak site
  • 185.234.217[.]99 – Known C2 node
  • 103.145.13[.]72 – Staging server for exfiltration

File & Registry Artifacts

  • Dropped executable → %AppData%\Local\Temp\svhost.exe
  • Registry modification → HKCU\Software\Microsoft\Windows\CurrentVersion\Run\svhost

Observed TTPs (MITRE ATT&CK)

  • Initial Access: Exploitation of public-facing apps (T1190), Spear-phishing (T1566)
  • Execution: PowerShell/Scripting (T1059)
  • Credential Access: LSASS dumping (T1003)
  • Persistence: Registry Run keys (T1547.001)
  • Exfiltration: Staging & compression (T1560), Exfiltration over Web/SMB (T1041)
  • Impact: File encryption (T1486), Data exposure via leak portals

How to get ahead of it

This incident reinforces a handful of defensive priorities, especially for insurance and finance:

1. Lock down the data itself

  • Encrypt sensitive customer and financial data at rest and in transit

2. Watch for exfiltration

  • Deploy DLP solutions
  • Monitor for abnormal outbound traffic

3. Segment what matters

4. Sharpen incident response

  • Update playbooks for data extortion-only attacks (without encryption)

5. Communicate honestly

  • If the breach is confirmed, notify regulators and affected customers promptly

6. Hunt and share

  • Monitor leak portals for brand exposure
  • Work with ISACs for cross-sector early warnings

7. Block known IOCs

  • Ingest threat feeds and block the IPs, domains, and hashes tied to LeakNet

Where this leaves us

The alleged LeakNet ransomware breach of SWAN General Limited is a reminder of how exposed the financial sector is to double extortion.

Even without encryption, the threat of exposure carries real weight, from regulatory fines to direct customer harm.

As these groups keep maturing, financial and insurance organizations have to get proactive:

  • Patch aggressively
  • Harden authentication and credential hygiene
  • Encrypt high-value datasets
  • Monitor IOCs
  • Share intelligence within the sector

When extortion is built on stolen data, protecting the systems isn't enough — you have to protect the data inside them, and know the moment someone reaches for it. That's the case we make in our breakdown of cyber deception lessons from the Synnovis hack. Want to see how planted decoy records catch exfiltration in progress? Book a Mine2 demo.

M2

Riya

Principal Threat Researcher, Mine2 Labs

Riya tracks active threat campaigns and APT tradecraft at Mine2 Labs, translating real-world attacker behaviour into practical detection ideas.

Share this article

Secure Your Network Today

Ready to implement advanced cyber deception in your organization? See how MINE2 can transform your threat detection capabilities.