On February 14, 2026, cryptocurrency custody provider BitGo appeared on the leak site of the incransom ransomware group, with the attackers claiming to have exfiltrated internal files during a ransomware incident.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Bitgo
Get alerted the next time Bitgo files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Bitgo’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Public reporting indicates that incransom added BitGo to its disclosures page on February 14, 2026. The listing states that internal files were taken during a ransomware attack. The exact number of people affected remains unknown, and the precise volume or sensitivity of the stolen data has not been independently verified. Available reporting describes the exposed material as internal files without specifying customer records, wallet keys, or personally identifiable information. BitGo has not yet issued a public statement confirming the breach or detailing what was taken.
Why This Matters for You and Your Family
When a financial services company like BitGo suffers a breach, anyone who has ever used its custody, trading, or wallet services could have information at risk. Even if you do not hold large crypto balances, smaller accounts, old email addresses, or linked payment details can appear in stolen files. That information can be combined with data from other breaches to build a profile of your finances, your home address, and the accounts you access. For families this means children’s shared family emails, joint investment accounts, or even school-related payment records could surface later. Once data leaves a company’s control, you and your family bear the long-term cost of monitoring, disputes, and potential fraud.
The Doxxing and Identity-Chain Risks
Ransomware groups rarely stop at one dataset. Internal files often contain employee directories, vendor contacts, customer support tickets, or configuration details that link usernames, email addresses, and phone numbers. These fragments become the starting point for doxxing chains. A single exposed email can lead to linked social-media handles, reused passwords on gaming platforms, and eventually full identity profiles. Credential leaks like this one frequently cascade into account takeovers on exchanges, email services, and children’s gaming accounts. The chain can reach family members who never directly interacted with BitGo but share the same household address or phone number listed in support records.