Hargreaves Lansdown suffered customer-facing IT problems, including account-balance glitches and service outages, between September 2025 and May 2026, prompting customer concern that the investment platform had been hacked. The company said the incidents were technical issues and maintained there was no evidence of a cyber incident or data breach.
In April 2026, the Bashe extortion group, also tracked as APT73 and Eraleign, added Hargreaves Lansdown to its Tor leak site and claimed it had stolen a database of 658,259 unique users; a sample later appeared on DarkForums. Subsequent analysis found the records were likely recycled or fabricated, with selectively chosen UK entries and overlaps with older breaches including Verifications.io and People Data Labs, indicating the group used the firm's recent outages to make a false breach claim appear credible and increase reputational pressure.

TTPs, infrastructure, and targeting history in one profile.
4 events from the most recent confirmed update back to the earliest known activity.
On 2026-04-27, ransomware.live reported Hudson Rock had detected infostealer-related exposure associated with Hargreaves Lansdown's hl.co.uk domain. The entry listed 1,141 compromised users, zero compromised employees, and four third-party employee credentials tied to the domain.
In May 2026, data presented as a sample of the alleged Hargreaves Lansdown breach appeared on DarkForums. Analysis described in the references found the records overlapped with older breaches including Verifications.io and People Data Labs, indicating the claimed breach was likely fabricated.
In April 2026, the Bashe extortion group, also known as APT73 or Eraleign, added Hargreaves Lansdown to its Tor leak site and claimed it had stolen a customer database containing 658,259 unique users.
Between September 2025 and March 2026, and reportedly into May 2026, Hargreaves Lansdown experienced account-balance glitches and service outages that prompted customer fears of hacking. The company said these were technical problems and stated there was no evidence of a cyber incident or data breach.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
5 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourceransomware.live
Open sourcebbc.co.uk
Open sourcearchive.is
Open sourceblog.bushidotoken.net
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.