A syndicate of cyber-criminals have accessed a global database used by businesses around the world to verify the credibility of users.
The World-Check database is maintained by the London Stock Exchange Group (LSEG), and allegedly fell into the hands of GhostR group who claimed the attack on Thursday. LSEG later verified the claim.
The breach, though genuine, was said to have occurred at an undisclosed third party.
“This was not a security breach of LSEG/our systems,” said an LSEG spokesperson. “The incident involves a third party’s data set, which includes a copy of the World-Check data file.”
The spokesperson said this was illegally obtained, and that they are liaising with the third party to protect their data and notify appropriate authorities.
The World-Check database is used globally, maintaining data on money launderers, terrorists, sketchy politicians, and other individual banks and financial institutions would want to avoid working with.
The database is accessed typically during Know Your Customer (KYC) checks, typically by banks to verify the credibility of potential clients.
The subscription-only service usually pulls from open sources like sanction lists, government sources, media publications, and regulatory enforcement lists.
Allegedly, the database contains more than five million records, and GhostR is threatening to start leaking the database soon.
The group told The Register that their first leak would include the information of thousands of individuals, including members royal families.
Recommended reading
- Police Crackdown Reveals Students Turning to Cyber-crime
- The Barrier of Entry for Fraud has Never Been Lower
- Police Anti-Fraud Operation Sees £19M of Assets Seized
The database includes full names and the categorisation of a person, such as their criminal status, but the information tends to range. Sometimes, job roles and birth dates are includes, while others have aliases, security numbers, and explanations on why the appear on the list included.
GhostR provided some of their stolen records to both The Register and TechCrunch, which included thousands of individuals, ranging from government official and diplomats, to high risk private company leaders.
World-Check has faced a data breach previously, in 2016, after a lapse in security at a third-party company.
World-Check’s labelling of individuals occasionally came under fire after the leak, as its branding of individuals as high risk can shut them out of opening bank accounts or applying for loans.





