On April 4, 2024, Chilean financial advisory firm acfin.cl appeared on the leak site operated by the Cactus ransomware group. The listing states that client confidential data, personal identification information including passports and driver’s licenses, financial statements, executives’ personal data, and even a security officer’s private photos and files were exfiltrated during a ransomware attack. The number of affected individuals remains unknown, and the disclosure does not specify exact record counts or ransom demands.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch acfin.cl
Get alerted the next time acfin.cl files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about acfin.cl’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Reported Details from the Leak Site
The Cactus leak page provides direct download links to what it claims is proof of the breach, hosted on both a primary onion address and a mirror. The data descriptions explicitly list client confidential data such as agreements and reports, personal identification information (passports, driver’s licenses), financial statements and reports, executives’ personal data, and private files belonging to a security officer. The listing does not quantify how many records were taken or name specific clients, but the breadth of material suggests both corporate and personally identifiable information were removed from acfin.cl’s systems.
Why This Matters for You and Your Family
If you or any member of your family worked with acfin.cl as a client, your personal documents may now sit on a dark-web server accessible to anyone who follows the onion links. Passports, driver’s licenses, and financial statements are high-value items for identity thieves. Even if you are not a direct client, the executives and employees whose private photos and files were taken could become targets for spear-phishing or blackmail that indirectly affects their professional networks, including everyday customers. Once this type of data leaves a company’s control, it circulates for years and can be combined with other leaks to build complete profiles.
The Doxxing and Identity-Chain Risks
Personal identification documents paired with financial records create long-term doxxing chains. A scanned passport can be linked to an email address, phone number, or gaming username discovered in another breach, allowing attackers to hijack accounts that belong to you or your children. Credential leaks of this nature frequently cascade into gaming-platform takeovers, where stolen logins are tested across Steam, Roblox, or Discord and then used to pressure families for ransom or simply to embarrass victims publicly. The security officer’s private files add another vector: attackers may use intimate photos or personal correspondence to coerce cooperation from inside the firm, increasing the chance that customer data is sold or published in full.