On July 11, 2024, UK-based data-centre specialist on365.co.uk appeared on the leak site operated by the qilin ransomware group. The listing states that internal files were exfiltrated during a ransomware attack; the exact number of records affected and the specific types of documents remain unknown because the disclosure provides no further detail.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch on365.co.uk
Get alerted the next time on365.co.uk files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about on365.co.uk’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Primary Disclosure Details
The qilin leak site entry states that on365 suffered a ransomware incident in which attackers extracted internal files before encrypting systems. No victim count, no list of exposed data categories, and no ransom demand figure are published on the page. The notification simply lists the company, the date of publication, and a sample of allegedly stolen material. Public reporting on qilin incidents indicates that such listings typically follow a double-extortion model: encryption plus the threat to publish or sell the stolen data if payment is not made.
Why This Matters for You and Your Family
Even when the precise data stolen is not disclosed, any breach at a specialist infrastructure provider like on365 carries real risk. Companies in this sector routinely hold detailed information about commercial customers, partner organisations, and sometimes the personal details of individual contacts. If your employer, your children’s school, your doctor’s surgery, or your own business uses on365-managed facilities, your information could sit inside the exfiltrated files. Internal files exfiltrated is the only description given, yet that single fact is enough to trigger concern for anyone whose name, address, phone number, email, or contract details might have been stored on those systems.
Doxxing and Identity-Chain Risks
When internal files leave a company’s control they often contain spreadsheets, email archives, project documents and configuration data that link names to addresses, phone numbers, email accounts and sometimes passwords or security questions. Attackers and subsequent buyers can chain these fragments together with data from other breaches to build a complete profile. A single leaked work email can expose your personal accounts if you have reused credentials. The same chain frequently reaches family members: a parent’s work contact list can expose a child’s name, school, or even gaming username. Credential leaks like this one cascade into account takeovers on Steam, Roblox, Fortnite and other platforms where children often share the same email address as a parent.