Our takedirewolf lists Leafwell on its leak site. Single leak-site posting, no filing, no victim statement. Claim only — unverified. If you're a customer: change that password anywhere you reused it, and watch your statements.Cyber Resilience desk
Sources (1)
- ransomware_live · ransomware_live
What this means for you — Security leader:Check for Leafwell in your third-party inventory; if present, invoke your vendor-incident playbook and request their IR status in writing.
What this means for you — Lean IT orgs:If you use or supply Leafwell: change any shared passwords today, watch account and transaction activity, and don't click 'urgent' emails about this incident.
What this means for you — MSP:Sweep client stacks for Leafwell dependencies and shared credentials; one leak-site claim can touch many of your clients at once.
What this means for you — Researcher:Unverified leak-site claim by direwolf; track for proof-of-data posts before citing. Victim statement, if any, supersedes.