// UNCLASSIFIED // CLEARED FOR PUBLIC RELEASE //
FILE BRC-hibpDTG 0600Z
Breach Record

CFGI

DISCLOSED 2026-03-06 · STOLEN CREDS · 248,235 RECORDS EXPOSED

In March 2026, the financial consulting and advisory firm CFGI was the target of a ShinyHunters "pay-or-leak" extortion campaign. The group subsequently publicised data allegedly obtained from CFGI comprising corporate contact information, including 243k unique email addresses, names, phone numbers and physical addresses.

The record

What we know

Disclosed
2026-03-06
Attack vector
Stolen Creds
Records exposed
248,235
Domain
cfgi.com
Data classes exposed
Email addressesEmployersJob titlesNamesPhone numbersPhysical addresses
Sources

Cited reporting

Similar vector · recent

Other stolen creds breaches on file

This page is the permanent ColdRecon entry for the CFGI disclosure. It updates if new public reporting emerges. All tracked breaches →

CFGI just lived through this. Your next prospect doesn't have to.

ColdRecon turns every disclosed breach into a daily intelligence brief from the seller's seat — normalized to the factors that move a deal, written in the Handler's voice. Request clearance and the first lands tomorrow at 0600.

Request Clearance →