On November 07, 2024, Chilean debt recovery firm Lexco appeared on the leak site operated by the meow ransomware group. The listing offers more than 28 GB of the company’s internal files, which were allegedly exfiltrated during a ransomware attack. Anyone whose overdue accounts, payment histories, or personal financial records were handled by Lexco may now have their information exposed.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Lexco
Get alerted the next time Lexco files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Lexco’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Details from the Leak-Site Listing
The meow leak site states that the data comes from a ransomware incident at Lexco, a company that handles pre-legal, legal, and extrajudicial debt collection for clients in healthcare, finance, automotive, public institutions, and real estate. The posting describes Lexco as a prominent Chilean firm with a multidisciplinary team focused on overdue-account resolution. It does not specify the exact number of affected individuals, the precise types of records taken beyond “confidential data,” or any ransom amount demanded. The listing simply presents the 28 GB archive as proof of successful exfiltration and invites interested parties to contact the group for samples or full access.
Why This Matters for You and Your Family
Debt-collection records frequently contain names, addresses, national identification numbers, phone numbers, email addresses, employment details, bank-account references, and payment histories. When such information reaches a ransomware leak site, it becomes permanently available to identity thieves, fraudsters, and stalkers. Even if you never directly hired Lexco, your data may have been shared with them by a hospital, bank, landlord, or government office that engaged their services. The exposure therefore reaches far beyond Lexco’s direct customers and into the households that interacted with any of its client sectors.
Doxxing and Identity-Chain Risks
Once internal files leave a company’s control, attackers and downstream buyers can link the stolen records to other breached datasets. A Chilean ID number paired with an email address can be cross-referenced against gaming accounts, social-media profiles, or earlier credential leaks. This creates an identity chain that reveals where you live, where your children attend school, and which online handles belong to each family member. Credential leaks of this kind often cascade into account takeovers on gaming platforms, allowing attackers to harass children directly or use their compromised profiles to gather still more personal information.