On August 14, 2024, Thompson Davis & Co., an independent private asset manager, appeared on the leak site of the BianLian ransomware group. The listing states that internal files were exfiltrated during a ransomware attack. The disclosure does not specify the number of people affected or list exact data types beyond claiming that internal files were taken.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Thompson Davis & Co
Get alerted the next time Thompson Davis & Co files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Thompson Davis & Co’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
Details from the Leak Site
The primary disclosure on the BianLian leak site indicates that Thompson Davis & Co. suffered a ransomware incident in which attackers exfiltrated internal files before encrypting systems. No victim count is provided, and the listing does not detail the volume or specific categories of information stolen. The site presents the company’s data as proof of compromise and typically sets a deadline for payment before full publication. Public reporting on BianLian shows this pattern is consistent: initial access, data theft, encryption, and then extortion through public shaming on their onion site.
Why This Matters for You and Your Family
When an asset manager like Thompson Davis & Co. loses control of internal files, the exposure can reach clients whose financial records, account numbers, tax documents, or personal identifiers sit inside those systems. Even if the exact contents remain unknown, the breach creates immediate risk for anyone who has worked with the firm. Your family’s investment history, contact details, and related financial data could now sit in an attacker’s archive, ready for sale or further extortion. Internal files exfiltrated in these incidents often contain spreadsheets, emails, and scanned documents that tie names, addresses, dates of birth, and Social Security numbers to financial activity.
Doxxing and Identity-Chain Risks
Stolen internal files rarely stay isolated. Attackers or buyers on underground forums combine them with other leaks to build complete identity profiles. An email address from this claimed breach can link to your brokerage login, which then chains to social-media handles, phone numbers, and children’s accounts. Once mapped, these connections enable account takeovers, targeted phishing, and doxxing campaigns that expose your home address or family relationships. Credential leaks like this one frequently cascade into gaming accounts belonging to you or your children, where stolen passwords grant entry and lead to further personal information harvesting.