On October 15, 2025, OCI International Holdings Limited (stock code 0329.HK) appeared on the leak site of the ransomware group known as RansomHouse, with the attackers claiming to have exfiltrated internal files from the Hong Kong-listed investment holding company.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch OCI International Holdings
Get alerted the next time OCI International Holdings files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about OCI International Holdings’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Public reporting indicates that RansomHouse posted data belonging to OCI International Holdings, a Cayman Islands-incorporated firm listed on the Hong Kong Stock Exchange since 2001. The company operates primarily through its subsidiary, OCI Asset Management Company Limited, which holds licenses from the Securities and Futures Commission for securities dealing, advising, and asset management. Its activities include cross-border mergers and acquisitions advisory as well as securities trading. A related entity, OCI Capital SPC, was incorporated in 2017 as a segregated portfolio company but reportedly held no active portfolios as of January 2025.
Available details describe the incident as a ransomware attack in which internal files were allegedly exfiltrated. The exact number of people whose information may have been exposed remains unknown, and the specific types of records posted have not been independently verified beyond the group's claim of stolen corporate documents. The primary source for the listing is the RansomHouse leak site, indexed by ransomware.live at the onion address provided at the end of this article.
Why This Matters for You and Your Family
When a financial services firm like OCI suffers a breach, the ripple effects reach ordinary investors, clients, and their households. Internal files can contain names, contact details, financial account references, transaction records, and correspondence that tie personal identities to investment activity. If your broker, advisor, or any fund you participate in uses similar providers, your information may already sit in overlapping datasets that attackers trade and combine.