On March 14, 2026, NextCapitalTrust appeared on the leak site of the ransomware group known as killsec, with the attackers claiming to have exfiltrated internal files during a ransomware incident.
Watch NextCapitalTrust
Get alerted the next time NextCapitalTrust files a breach with any US regulator — the filing, dated and sourced. A free single-company slice of Signals; no account needed.
We’ll email you only about NextCapitalTrust’s future breach filings and how to watch a whole vendor list — not general marketing. Unsubscribe any time.
Watching your whole vendor list (50 to 500 companies, by tier) is GalaxyWarden Signals.
What Public Reporting Shows
Public reporting on ransomware.live shows the listing includes screenshots and a partial sample of stolen data. The exact number of people whose information is contained in the files remains unknown. No confirmed count of exposed records has been published. The data consists of internal company documents rather than a structured database of customer records. As of the publication date, the group had not publicly released the full archive.
Why This Matters for You and Your Family
When a financial services firm like NextCapitalTrust suffers a breach, the documents taken can contain names, addresses, account numbers, tax details, or correspondence that tie directly to ordinary customers and their households. Internal files exfiltrated often hold the kind of personal paperwork families rely on for loans, investments, or estate planning. Once that material leaves the company’s control, it can surface in unexpected places. You and your family may not even know your information was involved until fraudulent activity appears on statements or unexpected mail arrives. The delay between breach and discovery is precisely why early action matters.
The Doxxing and Identity-Chain Risks
Stolen internal files frequently contain more than one piece of identifying information. An email address listed next to a phone number, a child’s school reference, or a shared family address can be stitched together with data from earlier breaches. These connections create an identity chain that lets attackers or opportunistic criminals move from one platform to the next. Credential leaks of this nature regularly cascade into gaming account takeovers, especially for children whose usernames and passwords are sometimes stored in family financial records or shared cloud folders. What begins as a corporate ransomware incident can quietly evolve into personal doxxing or repeated account compromises across services you and your children use every day.