ransomware Credible Mauritius (MU) insurance

SWAN Mauritius listed by the Qilin ransomware group

SWAN Mauritius

📅 18 August 2025
CompanySWAN Mauritius
CountryMauritius (MU)
Sectorinsurance
Breach date2025-08-18
People affectedNot disclosed
Ransomware groupqilin
Data typespolicyholder data, claims records, corporate information

Overview

The Qilin ransomware group has listed SWAN, a Mauritian insurance company, on its leak site. The company offers a range of insurance products. The listing appeared on 18 August 2025. At the time of analysis, the group's leak page was not reachable.

What was published

The group claims to have exfiltrated data from the insurer. The archive is expected to include policyholder records, claims documentation and corporate information.

Risks for affected individuals

  • Policyholders' personal and financial data may be exposed.
  • Claims records could enable fraud.
  • Employees' information may be included.

What remains unknown

  • The volume of records involved.
  • The exact contents of the leak.
  • Whether the data has been published elsewhere.

What affected people should do

Policyholders should monitor account activity and be cautious of unsolicited communications. SWAN should notify affected customers and regulators, review compromised systems, and provide guidance to those affected.

Sources

  • http://ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion/site/view?uuid=eaaae220-b8c4-350b-bd01-3f4668a26d8b