KickDown ESET company. No overpayments at 0% (renamed and update) Listed by donutleaks Ransomware Group
If you are a customer of Eset, here’s what is being claimed, and what it would mean for you.
This is what this note is now called. It's not about us "making" ESET. It's about the fact that: AT THE MOMENT I FUCKED THEIR NEW VERSION OF PREMIUM HOME SECURITY EDITION BEFORE THE PENTEST. == NO MORE == ....as the ever-condolent and praying “journalists” from... And now there will be a…
— from Donutleaks’s own leak-site posting. This is the group’s claim, quoted verbatim; it is not GalaxyWarden’s reporting and has not been independently verified.
Editor’s note: The claims described below originate from a ransomware group’s leak-site posting and have not been independently verified by GalaxyWarden. A listing of this kind is an assertion made by the group during an extortion attempt. It is not evidence that a breach occurred, and we report it as a claim rather than as a finding.
Eset customer?
See what’s already exposed about you — free, 15sWe check your email against known public breach records and the sites that publish your address, then show you what to do about each one. We don’t hold this company’s data. No account, no card.
ESET appeared on the donutleaks ransomware extortion site on July 21, 2024, with the listing titled “KickDown ESET company. No overpayments at 0% (renamed and update).” The entry claims the antivirus maker suffered a ransomware attack in which internal files were exfiltrated. The donutleaks group states it penetrated a new version of ESET’s Premium Home Security Edition before any pentest occurred, and the post includes mocking commentary aimed at security journalists. The leak-site listing does not quantify how many records were taken or name specific data types beyond “internal files.”
Primary Disclosure Details
The donutleaks page hosted on a Tor onion address states that ESET was compromised via ransomware and that attackers successfully exfiltrated internal files. It does not list a ransom amount, a negotiation timeline, or a sample of the stolen data. The note has been renamed and updated at least once since first publication, according to the site itself. Public reporting on the incident relies entirely on this primary leak-site posting; ESET has not yet issued a public breach notification that details the scope or states the claims.
Why This Matters for You and Your Family
When a major security-software vendor is hit, the ripple effects reach ordinary users who rely on that vendor’s products to protect their home computers, family photos, financial documents, and children’s devices. Even if the stolen material consists only of internal files today, tomorrow those files could contain support-ticket details, license keys, or partner contact lists that attackers later weaponize. July 21, 2024 marks the public confirmation that another household name in cybersecurity has been breached, underscoring that no company is immune and that your personal data may already sit inside one of the thousands of organizations that have suffered similar intrusions.
Advertisement
BATECH StudioWe build it.We run it.Web apps, AI pipelines and internal tools — under your brand, not ours.Tell us what you need →
BATECH Studio and GalaxyWarden share common ownership.
Doxxing and Identity-Chain Risks
Ransomware groups rarely stop at encryption. Once internal files leave the victim’s network they frequently surface on dark-web forums or are used to seed follow-on campaigns. A single email address or support ticket pulled from an antivirus company’s systems can link your gaming username, your child’s Roblox account, your phone number, and your home address into a single identity chain. That chain lets attackers pursue credential-stuffing attacks, SIM-swapping, or targeted extortion. Credential leaks like this one routinely cascade into account takeovers precisely because the same password or recovery details appear across consumer services and corporate support portals.
Donutleaks Track Record and Playbook
Public reporting attributes the donutleaks operation to a ransomware/extortion group that emerged in early 2024. The actors typically gain initial access through phishing, exploited remote-desktop services, or supply-chain compromises, exfiltrate sensitive files before deploying ransomware, then list the victim on their leak site when payment is refused. Notable prior targets have included mid-sized technology and manufacturing firms. Their public posts often mix technical claims with taunts directed at journalists and security researchers, a pattern repeated in the ESET listing. The group’s exact organizational structure remains unclear, but its consistent use of double-extortion—threatening both data publication and operational disruption—aligns with tactics seen across the broader ransomware ecosystem.
What to do
- Run a DoxxScan to map every link between your email addresses, usernames, phone numbers, and real-world identity so you can see exactly what chains back to the ESET breach.
- Rotate any password you ever used on ESET-related accounts or support portals and enable 2FA through an authenticator app rather than SMS.
- Enable continuous DoxxScan monitoring across 13.1B+ breach records and 100+ platforms so the next exposure of your data is caught in hours instead of months.
- Cover the entire household with DoxxScan family protection that extends to dependents and children’s gaming accounts, which often become the weakest link in doxxing chains.
- Let DoxxScan remediation specialists manage takedown requests on data-broker sites and extortion listings so you do not have to negotiate with threat actors yourself.
The incident shows once again that even companies whose business is digital defense can lose control of internal data. Staying ahead requires more than installing updates; it demands ongoing visibility into where your personal information actually travels. DoxxScan by GalaxyWarden delivers that visibility through continuous monitoring, AI-powered identity-chain mapping, and hands-on remediation by specialists who handle the cleanup for you and your family—including gaming accounts that attackers love to hijack. Source: donutleaks leak site (via ransomware.live)
What the free scan actually returns
Found on people-search siteswe remove these
These listings are live, public, and legal to remove — and removing them is what we do.
Found in breach recordsverifiedreported — unverified
Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.
Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.
For security and vendor-risk teams: a staff address in a leak does not mean you were breached — it usually means a third party was. We monitor a domain against 13.1B+ leaked records and tell you when one of your people appears. See what we would check →
Report details & sourcing
Related breaches
Aztec Software Listed by direwolf Ransomware Group
Engineering Software…
LOG Systems Listed by thegentlemen Ransomware Group
logsystem.pl zoominfo.com/c/log-systems/372786485 LOG Systems is a Polish software company based in …
dlp motive Listed by thegentlemen Ransomware Group
dlp-motive.de dlp motive is a German full-service event technology provider founded in 2007, success…