On September 18, 2025, the Qilin ransomware group added EOS Asset Management to its leak site, claiming that internal files had been exfiltrated from the Korean asset management firm. The company, which has operated on the Korean stock market since 2021 and manages a portfolio valued at 22 billion won ($15.8 million), specializes in brokerage services for lending. Public reporting indicates that customer and employee data may be among the stolen material, although the precise number of affected individuals remains unknown.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch EOS Asset management
Get alerted the next time EOS Asset management files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about EOS Asset management’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Reported Details of the Breach
Available reporting describes the incident as a ransomware attack in which Qilin claims to have downloaded internal documents before encrypting systems. The data was listed on the group’s dark-web leak portal, a standard step when victims do not pay the demanded ransom. No official statement from EOS Asset Management has been widely published, so details rely on the attackers’ own posting and secondary ransomware-tracking sites. The exposed information is reported to include internal files that could contain names, contact details, financial records, or account credentials tied to clients and staff.
Why This Matters for You and Your Family
When an asset management company loses control of internal files, the ripple effects reach ordinary people whose personal information sits in those records. If your broker, lender, or investment account is connected to EOS, your name, address, phone number, email, or financial identifiers may now be in criminal hands. Credential leaks like this one frequently cascade into account takeovers, identity theft, and harassment that can affect your family for years. Children’s information linked to household accounts is especially vulnerable because gaming usernames, parent-linked emails, and family addresses often appear together in the same datasets.
The Doxxing and Identity-Chain Risks
Ransomware operators rarely stop at dumping one spreadsheet. Once personal details surface, other criminals combine them with data from previous breaches to build detailed identity chains. A phone number from this leak can be matched to a gaming account, an old password can unlock social media, and an address can tie everything to your real name. The result is doxxing that exposes you and your family to harassment, fraud, and targeted scams. Public reporting shows these chains frequently begin with financial or brokerage leaks exactly like this one.