On March 16, 2025, the UK auction house and estate agent Kivells appeared on the leak site of the Play ransomware group, with the attackers claiming to have exfiltrated internal files during a ransomware incident.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Kivells
Get alerted the next time Kivells files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Kivells’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Public reporting indicates that Kivells, a long-established firm handling property auctions, livestock sales and estate agency across Devon and Cornwall, was listed by the Play group on its dark-web portal. The listing states that internal files were taken, although the precise volume and exact nature of the data have not been independently verified. No confirmed victim count has been published, and it remains unclear whether customer records, employee details or financial documents were among the stolen material. The Play group typically posts samples and sets a deadline for payment before releasing or selling the full archive; at the time of writing the deadline for Kivells had not yet expired.
Why This Matters for You and Your Family
When a business that handles property transactions, valuations or livestock records is breached, the information it holds often includes names, addresses, phone numbers, email accounts, bank details and sometimes copies of identity documents. If you or your family have bought or sold property through Kivells, bid at one of their auctions, or used their estate-agency services, your personal data may now sit in an attacker-controlled archive. That data does not expire. It can be sold on criminal forums, used for identity theft, or combined with other leaks to build a detailed profile of your household. Ordinary families who simply conducted everyday business are now at elevated risk of fraud, phishing and unwanted contact.
The Doxxing and Identity-Chain Implications
Ransomware leaks rarely stop at one company. A single exposed email or phone number can be cross-referenced against dozens of other breaches, gaming platforms, social-media accounts and data-broker records. Attackers chain these fragments together to locate your home address, map family relationships and identify children’s online handles. Credential leaks of this kind frequently cascade into account takeovers on gaming services, email and banking portals. Once attackers control an email address linked to your child’s Roblox, Fortnite or Steam account, they can pivot to social engineering or direct extortion. The speed and automation of these identity chains mean that waiting for notification letters is no longer sufficient.