On January 27, 2026, the Genesis ransomware group added IMA Diligence Services, a division of IMA Financial Group, to its leak site, claiming that internal files had been exfiltrated during a ransomware attack on the financial services provider.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch IMA Financial Group
Get alerted the next time IMA Financial Group files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about IMA Financial Group’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Public reporting indicates the incident involves internal files stolen from IMA Diligence Services. The listing appeared on the Genesis leak site, hosted on the dark web address linked through ransomware.live. No exact victim count has been released, and the precise volume or sensitivity of the documents remains unclear from available information. The breach follows the typical ransomware pattern of initial access, data theft, and subsequent extortion pressure.
January 27, 2026 marks the public confirmation date when the group listed the company. Industry research from sources such as DoxxScan™ continuous monitoring indicates that financial service providers frequently appear in such incidents because they hold sensitive client records that can be leveraged for further attacks.
Why This Matters for You and Your Family
If you or anyone in your household has worked with IMA Diligence Services or IMA Financial Group, your personal or financial information may now sit in a ransomware data set. Even when exact numbers are unknown, these leaks often contain names, addresses, Social Security numbers, bank details, or client correspondence that criminals can sell or use directly.