~/f4n6 $ grep -r "Ransomware: Global Secret Group named Portman Finance Group (GB)" ./investigations/ --include="*.md"

Ransomware: Global Secret Group named Portman Finance Group (GB)

Jeff Davies 26 Jul 2026 5 min read

1. Executive summary

On 2026-07-26, the actor "Global Secret Group" listed Portman Finance Group (UK, ~£300M revenue, 1,000–5,000 employees) as a ransomware victim on its leak site, claiming 209 GB of data across 255,244 files and 34,852 folders. Attribution to "Global Secret Group" is unconfirmed — the actor has no MITRE ATT&CK profile in our verified reference data, and the claim rests solely on the ransomware.live listing. Portman Finance Group is a UK financial services firm; the claimed data volume, if accurate, represents a significant data-exfiltration event with potential regulatory and operational impact for EMEA financial services clients with exposure to the victim.

2. Regulatory framing

Article Trigger (the fact in this item) Practical impact
DORA Art. 19: reporting of major ICT-related incidents to competent authorities A UK financial services firm (~£300M revenue) has been publicly named as a ransomware victim with 209 GB of claimed exfiltrated data — scale and public disclosure create a plausible major-incident classification trigger. If Portman Finance Group is subject to DORA, the public listing and data volume likely trigger major-incident reporting timelines. Clients with third-party exposure to Portman should assess whether the incident affects their own ICT services and reporting obligations.
DORA Art. 28: ICT third-party risk — general principles Hudson Rock data indicates 2 third-party employee credentials associated with the victim domain, raising supply-chain exposure questions for any client relying on Portman Finance Group as an ICT third-party provider. Clients using Portman as a financial services provider should review contractual incident-notification clauses and assess whether their own ICT services are impacted.

No NIS2 or UK NIS article is specifically engaged beyond generic incident-response obligations, as the trigger facts are not distinctive to those regimes' specific requirements.

3. Technical analysis & attack chain

Attribution caveat: "Global Secret Group" has no MITRE ATT&CK profile in our verified reference data. Attribution rests entirely on the ransomware.live listing — a single source. Treat the actor name as unconfirmed until corroborated by independent threat-intelligence reporting.

What is confirmed (single-sourced to ransomware.live)

  1. Public listing: On 2026-07-26, a ransomware leak site entry attributed to "Global Secret Group" named Portman Finance Group (portmanfinancegroup.co.uk) as a victim.
  2. Claimed data exfiltration: 209 GB across 255,244 files and 34,852 folders. The listing implies data theft; no confirmation of encryption is provided in the source.
  3. Victim profile: UK-based financial services firm, ~£300M revenue, 1,000–5,000 employees.
  4. Third-party credential exposure: Hudson Rock data associated with the ransomware.live listing reports 2 third-party employee credentials and 0 compromised employees/users. This may indicate initial access via a third-party credential compromise, but this is inferential — the source does not state a causal link.
  5. Campaign context: Global Secret Group has listed at least 5 other victims on ransomware.live (SPDM/BR, Novum Energy/US, OFS/US, Cold Front Distribution/US, Uniview Technologies/CN), with claimed data volumes ranging from 209 GB to 1.5 TB. This suggests an active campaign with data exfiltration as the primary extortion lever.

What is NOT available in the source material

  • No initial access vector is confirmed (no CVE, exploited service, or phishing lure identified).
  • No malware name, family, or technical capability is described.
  • No C2 infrastructure, persistence mechanisms, or lateral movement techniques are documented.
  • No encryption behaviour is confirmed — the listing may represent data-theft extortion without file encryption.
  • No ransom demand amount, deadline, or ransom-note text is provided.

4. Mitigation & containment

P1 — Within 24 hours

  • Determine whether your organisation has a direct business or ICT relationship with Portman Finance Group. If yes, invoke your third-party incident notification clauses and request a formal incident status update.
  • Search email, DNS, and web-proxy logs for portmanfinancegroup.co.uk to identify any recent or ongoing communication with the victim domain.
  • If Portman is a vendor or data partner, assess what data or systems may be exposed via that relationship and document for potential regulatory notification.

P2 — Within 72 hours

  • Review Hudson Rock or infostealer intelligence for any credentials associated with your own third-party vendors — the Portman listing highlights that third-party credential exposure (2 third-party employee credentials reported) is a viable attack vector for this actor's campaign.
  • If any of your third-party suppliers appear in the broader Global Secret Group victim list (SPDM, Novum Energy, OFS, Cold Front Distribution, Uniview Technologies), assess exposure and impact accordingly.
  • Block and monitor the victim domain portmanfinancegroup.co.uk if there is no legitimate business need for access, as a precaution against potential supply-chain compromise.

P3 — Within 7 days

  • Review third-party risk management processes against DORA Art. 28 and Art. 30 requirements — ensure contractual incident-notification timelines are sufficient for ransomware events with public disclosure.
  • Update threat-intelligence monitoring for "Global Secret Group" to track further victim claims and any emerging TTPs, IOCs, or malware associations from independent researchers.

5. Indicators of compromise

No atomic indicators of compromise (IPs, domains, hashes, file paths, registry keys) are available in the source material. The only domain referenced (portmanfinancegroup.co.uk) is the victim's legitimate corporate domain, not a malicious infrastructure indicator.

Behavioural indicators

Behaviour Where to observe Confidence
Third-party employee credential exposure on victim domain Hudson Rock infostealer intelligence platform Low — single-sourced; 2 credentials reported, no confirmed causal link to the ransomware event
Public leak-site listing with large-volume data claims (200+ GB) Ransomware.live / actor leak site monitoring Medium — consistent with 5+ other Global Secret Group victim listings
Data-theft extortion without confirmed encryption Actor leak site, victim communications Low — inferred from absence of encryption claims in source; not confirmed

6. Detection

Insufficient indicators to author detection rules. The source material contains no malware artefacts, command-line strings, file paths, registry keys, mutex names, network indicators, or other threat-specific strings that would support a functional YARA or Sigma rule. The victim domain name is not a threat artefact.

7. Sources

  • Ransomware.live — "Ransomware: Global Secret Group named Portman Finance Group (GB)" — https://www.ransomware.live/id/UG9ydG1hbiBGaW5hbmNlIEdyb3VwQEdsb2JhbCBTZWNyZXQgR3JvdXA= — 2026-07-26
  • Ransomware.live — "Ransomware: Global Secret Group named SPDM (BR)" — https://www.ransomware.live/id/U1BETUBHbG9iYWwgU2VjcmV0IEdyb3Vw — (corpus context)
  • Ransomware.live — "Ransomware: Global Secret Group named Novum Energy (US)" — https://www.ransomware.live/id/Tm92dW0gRW5lcmd5QEdsb2JhbCBTZWNyZXQgR3JvdXA= — (corpus context)
  • Ransomware.live — "Ransomware: Global Secret Group named OFS (US)" — https://www.ransomware.live/id/T0ZTQEdsb2JhbCBTZWNyZXQgR3JvdXA= — (corpus context)
  • Ransomware.live — "Ransomware: Global Secret Group named Cold Front Distribution (US)" — https://www.ransomware.live/id/Q29sZCBGcm9udCBEaXN0cmlidXRpb25AR2xvYmFsIFNlY3JldCBHcm91cA== — (corpus context)
  • Ransomware.live — "Ransomware: Global Secret Group named Uniview Technologies (CN)" — https://www.ransomware.live/id/VW5pdmlldyBUZWNobm9sb2dpZXNAR2xvYmFsIFNlY3JldCBHcm91cA== — (corpus context)

8. Adverse Trace position

This is a single-sourced ransomware claim with unconfirmed actor attribution — "Global Secret Group" has no MITRE ATT&CK profile and no independent corroboration of TTPs, malware, or infrastructure exists in the available data. The victim is a UK financial services firm with ~£300M revenue, and the claimed 209 GB exfiltration volume is credible in the context of the actor's other listings (range 209 GB–1.5 TB across 6 victims). For EMEA financial services clients, the primary near-term risk is third-party exposure: if Portman Finance Group is a vendor, data partner, or counterparty, clients should assess data exposure and regulatory notification obligations under DORA Art. 19 and Art. 28. We will monitor for independent confirmation of the breach, emergence of IOCs or TTPs attributed to "Global Secret Group," and any statement from Portman Finance Group or UK regulatory authorities. Confidence in this advisory is LOW pending corroboration — verify before enforcement.


Read the original source →

Published via PulseTrace — Adverse Trace threat intelligence.

Post this to LinkedIn
Formatting is converted automatically — headings, bullets, a link back & hashtags. Paste straight in.
J
Jeff Davies