Chicago Trading Company was listed on the LockBit 3.0 ransomware leak site on November 17, 2023. The proprietary trading firm, founded in 1995 and active in equities, interest rates, and commodities, is claimed to have had internal files exfiltrated during a ransomware attack. Anyone whose personal or financial information passed through the firm’s systems may now be exposed.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch chicagotrading.com
Get alerted the next time chicagotrading.com files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about chicagotrading.com’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Primary Disclosure Details
The LockBit 3.0 leak site listing states that internal files were exfiltrated from Chicago Trading Company. The notification does not quantify the number of records affected, list specific data types, or disclose any ransom demand. It simply states that data was taken and is now published on the extortion platform. Public reporting on LockBit 3.0 indicates the group typically posts samples or full archives after victims ignore their deadlines.
Why This Matters for You and Your Family
When a trading firm’s internal files reach a public leak site, the exposure often reaches beyond employees. Clients, counterparties, vendors, and their families can have names, addresses, Social Security numbers, bank details, or tax documents included in the stolen material. Even if the listing does not specify what was taken, the mere presence of the company on the LockBit 3.0 site means your information could already be circulating among criminals who buy and resell such datasets. The breach therefore creates immediate identity-theft and fraud risk for ordinary people connected to the firm.
Doxxing and Identity-Chain Implications
Ransomware leaks rarely stop at one dataset. Criminals combine the newly released files with earlier breaches to build detailed identity chains that link email addresses, phone numbers, usernames, and real-world identities. A single leaked trading account statement can expose your home address, which then ties to children’s school records or gaming accounts. Once these connections are mapped, targeted phishing, SIM-swapping, and account takeovers become far easier. Credential leaks of this kind frequently cascade into gaming-platform compromises because the same passwords or recovery emails are reused across work, finance, and entertainment services.