On November 25, 2024, real estate investment CRM provider Investment Dominator appeared on the leak site of the killsec Ransomware Group. The listing states that internal files were exfiltrated during a ransomware attack. The company, whose platform helps users manage contacts, property records, marketing campaigns, and deal flow for land and house investing, has not yet published a public breach notification detailing the exact scope.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch inv[...]nator
Get alerted the next time inv[...]nator files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about inv[...]nator’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Primary Disclosure Details
The killsec leak-site posting, accessible via the ransomware.live mirror at the onion address provided, states that Investment Dominator data was taken in a ransomware incident. The listing does not specify the volume of records affected, the precise date of initial compromise, or the full inventory of files stolen. It simply states that internal files were exfiltrated and are now hosted for download by anyone who pays the group’s fee or waits for potential free release. No customer count or list of exposed data fields is published in the primary disclosure. Public reporting on killsec’s past behavior indicates the group often posts samples as proof before escalating extortion pressure.
Why This Matters for You and Your Family
If you or anyone in your household has used Investment Dominator to store contact lists, property details, or marketing data, your information may now sit inside a criminal marketplace. Real estate investors frequently enter personal phone numbers, home addresses, email accounts, and financial notes about deals. When that data leaves the company’s control, it can be combined with other leaks to build detailed profiles. Even if the exact number of affected records remains unknown, the exposure creates immediate risk for identity theft, targeted phishing, or physical scams aimed at people who appear to own investment property.
Doxxing and Identity-Chain Risks
Ransomware leaks rarely stay isolated. A single email or phone number allegedly taken from Investment Dominator can be cross-referenced against dozens of other breaches to link your online handles, gaming accounts, and family members. Children’s usernames on Roblox, Fortnite, or Discord often reuse the same password or recovery email as a parent’s investment portal. Once attackers map those connections, account takeovers cascade quickly into full doxxing. The result is harassment, swatting, or extortion attempts that reach every device and every member of the household.