On March 9, 2025, the ransomware group LockBit3 added acimfunds.com to its public leak site, claiming that internal files had been exfiltrated from the asset management firm during a ransomware attack.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch acimfunds.com
Get alerted the next time acimfunds.com files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about acimfunds.com’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Public reporting indicates that LockBit3 posted a notice on its onion site listing acimfunds.com as a victim. The firm manages capital for institutional investors, family offices, and high-net-worth individuals with a focus on niche commodities strategies tied to the energy transition. Available reporting describes the exposed material as internal files; the exact volume and full list of data types remain unconfirmed by the company. No specific victim count for individual clients has been released. The posting follows the group’s typical pattern of publishing proof of exfiltration after an initial encryption attempt.
Why This Matters for You and Your Family
When an investment firm’s internal documents appear on a ransomware leak site, the information inside can include names, addresses, account numbers, tax details, and correspondence tied to clients. If your family has any relationship with acimfunds.com, those records may now sit in criminal hands. Credential leaks from such incidents often cascade into account takeovers elsewhere because people reuse the same email addresses and passwords across services. For ordinary families this can mean sudden identity theft, fraudulent loans opened in your name, or targeted scams that reference real financial details only an insider would know.
The Doxxing and Identity-Chain Implications
Stolen internal files frequently contain spreadsheets or databases that link personal identifiers to email addresses, phone numbers, and sometimes dates of birth. Attackers chain these fragments together with data from previous breaches to build complete profiles. A single leaked document can expose not only adults but also dependents listed on account forms. Once the chain begins, doxxing escalates quickly: attackers move from financial data to social-media handles, then to children’s gaming accounts that share the same family email. Public reporting shows these chains frequently end in harassment, SIM-swapping attempts, or extortion demands directed at the household.