What we're tracking
The LeakNet ransomware group has claimed responsibility for a data breach at SWAN General Limited, a Mauritius-based insurance provider.
On the group's dark web leak portal, the attackers say they exfiltrated hundreds of gigabytes of sensitive data, including:
- Customer identification documents (IDs, passports)
- Insurance policy contracts and claims records
- Financial documents and transaction logs
- HR files and internal communications
Nobody has independently verified the dump yet, so treat the specifics with caution. But the claim fits a pattern I watch closely on my threat-intel desk: financial and insurance institutions keep getting picked off because they sit on enormous piles of personally identifiable information (PII) and sensitive business data.
The claim, in brief
| Field | Details |
|---|---|
| Date of Claim | August 13, 2025 |
| Threat Actor | LeakNet ransomware group |
| Target Organization | SWAN General Limited (Mauritius) |
| Alleged Data Theft | Hundreds of GB of internal and customer data |
| Extortion Tactic | Threat to leak stolen data unless ransom paid |
The posting lines up with LeakNet's double extortion model, where data gets stolen before encryption and then used as leverage during ransom negotiations.
Who is LeakNet?
LeakNet is a newer group, but it's grown fast. We've tracked its activity since late 2024.
What sets them apart
- Runs a "double extortion" playbook: encrypt, exfiltrate, then leak
- Operates a darknet leak portal where it lists victims
- Goes after sectors with high-value data: insurance, healthcare, manufacturing, banking
Where they've shown up (2024–2025)
- Manufacturing targets in Asia
- Healthcare providers in Europe
- Banks and insurers in Africa
The throughline is money. LeakNet exposes sensitive records, then resells them in underground markets or recycles them into the next round of attacks.
Why this could hurt
If the SWAN General Limited claim holds up, the fallout could include:
- Customer Exposure → Policyholder PII and ID documents are perfect fuel for identity theft and fraud
- Regulatory Scrutiny → A possible investigation under the Mauritius Data Protection Act (GDPR-aligned)
- Operational Disruption → Stolen data erodes trust and can knock operations sideways
- Secondary Threats → Exposed data feeds phishing, social engineering, and insider attacks
That last point is the one defenders underrate. I've watched a single leaked dataset seed credential-stuffing and account-takeover waves months after the original breach went quiet.
Indicators of Compromise (IOCs)
⚠️ Note: These IOCs are based on past LeakNet campaigns—specific artifacts tied to SWAN General Limited have not been confirmed.
Malware Hashes
b37a3f93f9f5c9d3a9a1a2f0a2a8c933– Ransomware loader (SHA-256)c11f2a0a4b1a0a76bbf0d7d7f7ac445e– Credential harvester (SHA-256)
C2 Infrastructure (2025)
leaknet[.]onion– Darknet leak site185.234.217[.]99– Known C2 node103.145.13[.]72– Staging server for exfiltration
File & Registry Artifacts
- Dropped executable →
%AppData%\Local\Temp\svhost.exe - Registry modification →
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\svhost
Observed TTPs (MITRE ATT&CK)
- Initial Access: Exploitation of public-facing apps (T1190), Spear-phishing (T1566)
- Execution: PowerShell/Scripting (T1059)
- Credential Access: LSASS dumping (T1003)
- Persistence: Registry Run keys (T1547.001)
- Exfiltration: Staging & compression (T1560), Exfiltration over Web/SMB (T1041)
- Impact: File encryption (T1486), Data exposure via leak portals
How to get ahead of it
This incident reinforces a handful of defensive priorities, especially for insurance and finance:
1. Lock down the data itself
- Encrypt sensitive customer and financial data at rest and in transit
2. Watch for exfiltration
- Deploy DLP solutions
- Monitor for abnormal outbound traffic
3. Segment what matters
- Isolate sensitive workloads and backups so attackers can't move laterally as freely. We dug into how deception breaks that movement in ransomware lateral movement defense.
4. Sharpen incident response
- Update playbooks for data extortion-only attacks (without encryption)
5. Communicate honestly
- If the breach is confirmed, notify regulators and affected customers promptly
6. Hunt and share
- Monitor leak portals for brand exposure
- Work with ISACs for cross-sector early warnings
7. Block known IOCs
- Ingest threat feeds and block the IPs, domains, and hashes tied to LeakNet
Where this leaves us
The alleged LeakNet ransomware breach of SWAN General Limited is a reminder of how exposed the financial sector is to double extortion.
Even without encryption, the threat of exposure carries real weight, from regulatory fines to direct customer harm.
As these groups keep maturing, financial and insurance organizations have to get proactive:
- Patch aggressively
- Harden authentication and credential hygiene
- Encrypt high-value datasets
- Monitor IOCs
- Share intelligence within the sector
When extortion is built on stolen data, protecting the systems isn't enough — you have to protect the data inside them, and know the moment someone reaches for it. That's the case we make in our breakdown of cyber deception lessons from the Synnovis hack. Want to see how planted decoy records catch exfiltration in progress? Book a Mine2 demo.
Riya
Principal Threat Researcher, Mine2 Labs
Riya tracks active threat campaigns and APT tradecraft at Mine2 Labs, translating real-world attacker behaviour into practical detection ideas.
Recent Articles
Need Security Help?
Protect your organization with MINE2's cyber deception platform.
