On October 23, 2025, translation and transcription provider Vanan Online Services appeared on the leak site of the ransomware group killsec. The company, which handles sensitive client audio, video, and written materials in more than 100 languages, is claimed to have had internal files exfiltrated during a ransomware attack. While the exact number of affected individuals remains unknown, anyone who used Vanan’s services for personal, family, medical, legal, or business documents may have had their data exposed.
Already exposed?
You can’t unleak data. You can take away what it’s worth.
A leaked record is where it starts, not where it ends. What turns it into your front door is the look-up sites publishing your address beside your name — and those are what an AI reads when somebody asks about you. The free scan shows you both. We write to 580 companies.
See what is exposed about you — free scan →Watch Vanan Online Services
Get alerted the next time Vanan Online Services files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about Vanan Online Services’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Public reporting indicates that killsec listed Vanan Online Services on its leak portal and published samples of the stolen material. The compromised data consists of internal files rather than a simple customer database. Available reporting describes the incident as a classic ransomware deployment in which the attackers encrypted systems, exfiltrated documents, and later posted the material when demands went unmet. No confirmed total of impacted records or specific client lists has been released by the company or the threat actors.
Why This Matters for You and Your Family
If you or anyone in your household has ever sent personal recordings, family videos, legal contracts, medical reports, or school assignments to a translation service, your private information could now sit in an attacker’s archive. These files often contain full names, addresses, phone numbers, email accounts, dates of birth, and sometimes financial or health details. Once such material leaves a company’s control, it can surface on dark-web marketplaces or be used to build profiles that make your family an easier target for identity theft, phishing, or harassment. Children’s school projects or voice recordings are especially concerning because they frequently link back to family addresses and parent accounts.
The Doxxing and Identity-Chain Risk
Stolen translation files rarely stay isolated. A single document can contain an email address that matches one used for online shopping, a phone number tied to a child’s gaming account, or a home address listed on a family video file. Attackers chain these fragments together, turning one breach into a map of your entire digital life. This is exactly how credential leaks cascade into account takeovers and full doxxing campaigns. Even if you never reused passwords, the combination of personal documents and contact details gives criminals enough context to impersonate you or pressure your family.