On January 24, 2026, the ransomware group Safepay added interr.com to its leak site and began publishing what it claims are internal files exfiltrated from the London-based security and risk-management company.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch interr.com
Get alerted the next time interr.com files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about interr.com’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Interr is a privately held firm headquartered at The Loom, 14 Gower’s Walk, London. Public reporting indicates the company provides security and risk-management services. The Safepay leak site lists the firm and has started releasing samples of allegedly stolen internal documents. No confirmed total number of affected individuals has been published, and the precise volume and sensitivity of the files remain unclear from available reporting. The posting appeared on the group’s onion site, which is tracked by ransomware.live.
Why This Matters for You and Your Family
When a security company’s own internal files are stolen, the data inside can include client records, contracts, employee details, and contact information that ultimately points back to ordinary people like you. Internal files exfiltrated in a ransomware attack often contain spreadsheets, emails, or databases that list names, addresses, phone numbers, and sometimes dates of birth or national insurance numbers. Once those details leave the company’s control, they can be sold, swapped, or used to target you and your family with identity theft, phishing, or physical threats. Even if you have never heard of Interr, your information may have been entrusted to them by an employer, insurer, bank, or other service you use every day.
The Doxxing and Identity-Chain Risk
Ransomware leaks rarely stop at one company. A single exposed email or phone number can be fed into automated tools that link it to your usernames on social media, shopping sites, and gaming platforms. That process creates an identity chain: an attacker who obtains your work email from the Interr files can quickly find your personal accounts, your children’s usernames, and the shared family address. Credential leaks like this one regularly cascade into account takeovers. Gaming accounts belonging to you or your children are especially vulnerable because they often reuse passwords or recovery emails that appear in business breaches. The result can be doxxing, harassment, or financial fraud that starts from one company’s mistake and spreads across your entire digital life.