Direwolf Ransomware Claim Targets RelyComply

Unverified Direwolf claim names UK AML platform RelyComply

A Direwolf ransomware claim has named RelyComply AML Platform as an alleged victim. However, the leak-site listing contains no evidence that an intrusion, data theft or system encryption occurred.

The listing was reported on 9 September 2026 and should be treated as an unconfirmed allegation. Organisations using RelyComply should monitor official communications, but the information currently available does not indicate that urgent technical action is required.

What the Direwolf ransomware listing says

RedPacket Security reported that the Direwolf ransomware group had added a victim labelled “RELYCOMPLY AML PLATFORM” to its dark web leak site. The accompanying report describes RelyComply as a UK provider of financial software, while the victim label identifies its anti-money laundering platform.

The listing date is 9 September 2026. This is the date on which the claim was reported, not a confirmed compromise date. No information establishes when an alleged intrusion began, when it might have been detected or whether any contact took place between the organisation and the threat actor.

The Direwolf ransomware post reportedly includes only the victim name and group attribution. It does not contain descriptive text explaining the claim, and there are no screenshots, sample files or other images offered as proof.

No ransom demand or payment deadline is disclosed. The listing also provides no information about negotiations, communications with the alleged victim or any threat to publish data by a specified date.

No confirmation of encryption or data theft

Crucially, the listing does not say whether RelyComply systems were encrypted. It also does not specify whether data was accessed, copied or removed from the organisation’s environment.

This distinction matters because a name appearing on a criminal leak site is not, by itself, evidence of a ransomware infection. Threat actors may publish names following an intrusion, an unsuccessful extortion attempt, the acquisition of data from another source or, in some cases, without any substantiated access at all.

RedPacket Security states that it did not obtain, download, host, view or republish any allegedly stolen material. Its report was generated from a redacted and automated collection of information appearing on the Direwolf dark web page.

What remains unknown about the Direwolf ransomware claim

The report contains no technical account of how the alleged attack occurred. There is no identified initial access route, such as a compromised account, malicious email, exposed remote service or exploited software vulnerability.

No malware samples, file extensions, ransom notes, attacker infrastructure or indicators of compromise are included. Consequently, defenders cannot use the listing to identify a specific intrusion pattern or search for artefacts associated with this particular claim.

The information available also does not identify any affected RelyComply product, service, application or hosting environment. Despite the victim label referring to the AML platform, it would be unsafe to infer that the platform itself was compromised.

No product versions are named, and no vulnerability identifier or security defect is cited. There is therefore no basis for concluding that customers run an exposed version or that a flaw in RelyComply software is being exploited.

Information absent from the listing

As at 9 September 2026, the public report provides no substantiation for several details normally needed to assess a ransomware incident:

  • A confirmed date or duration for the alleged compromise.
  • The systems, applications, environments or product versions involved.
  • The method used to obtain initial access.
  • Evidence that files or databases were accessed or removed.
  • Confirmation that systems were encrypted or disrupted.
  • The type, volume or ownership of any allegedly affected data.
  • A ransom amount, payment deadline or negotiation record.
  • Technical indicators that customers can use for threat hunting.

There is also no reported evidence that customer environments were accessed through RelyComply. The listing does not establish a supply chain incident, and it does not indicate that credentials, integrations or customer records have been exposed.

Credibility of the Direwolf ransomware allegation

The report carries a specific verification warning about Direwolf ransomware listings. Claims attributed to the group have reportedly included unverified or fabricated victims, making independent corroboration particularly important.

This warning does not prove that the RelyComply allegation is false. It means the criminal group’s own statement cannot be considered reliable evidence without supporting material or confirmation from another credible source.

At present, the strongest conclusion supported by the report is simply that a name matching RelyComply AML Platform appeared on a site attributed to Direwolf. The scope, impact and authenticity of the alleged incident remain unknown.

There is also no documented exploitation status for a product vulnerability because no vulnerability has been identified. Reports that describe the listing as a confirmed breach, ransomware infection or data leak would go beyond the available evidence.

Why the RelyComply claim matters

RelyComply provides anti-money laundering software, so any confirmed security incident could be relevant to organisations using its services. Depending on the affected environment, an incident involving this type of provider could raise questions about sensitive compliance information, integrations and third-party access.

None of those outcomes has been established in this case. The immediate significance of the Direwolf ransomware claim is that it creates a potential third-party risk signal requiring verification, rather than proof of customer exposure.

What organisations should do now

RelyComply users should avoid treating the criminal listing as a confirmed compromise. A proportionate response is to monitor for direct vendor notices, regulatory disclosures or independently verified technical findings.

  • Confirm that security and supplier-risk contacts are subscribed to official RelyComply communications.
  • Review what information, integrations and access permissions are associated with the service.
  • Preserve relevant authentication and integration logs in case later disclosures justify investigation.
  • Ask established vendor contacts for clarification through trusted channels, rather than responding to attacker material.
  • Escalate only if credible evidence indicates that specific systems, accounts or data may be affected.

Without indicators of compromise, a named vulnerability or evidence of customer impact, broad emergency changes could create unnecessary disruption. The priority is to maintain visibility and reassess if RelyComply or another reliable source publishes substantiated details.

Originally reported by redpacketsecurity.com.

Share this bulletin

About the Author

Headshot of Jonny Pelter, leading cyber security expert in the UK and CISO

Jonny Pelter

Partner

  • CIPM
  • CIPP/E
  • CISSP
  • CISM
  • CRISC
  • ISO27001
  • Prince2
  • MSc
  • BSc

Jonny Pelter

Jonny is a Founding Partner at CyPro and executive group level CISO who has worked closely with the British intelligence agencies NCSC and GCHQ.

An ex-professional rugby player and originating from KPMG and Deloitte, Jonny has a wealth of experience across numerous sectors including technology, critical national infrastructure, financial services, oil & gas, insurance, betting, pharmaceuticals and utilities.

Jonny is a leading cyber security expert in the UK, having featured on national media for his professional commentary such as BBC News, iPlayer, Telegraph and Times Radio.

View Profile
Back to Bulletins

Related CyPro Services

  • Managed Detection and Response (MDR)

    Managed Detection and Response (MDR) is an end-to-end managed service designed to help organisations detect, analyse and respond to cyber threats quickly and effectively. It...
    View Service
CyPro Cookie Consent

Hmmm cookies...

Our delicious cookies make your experience smooth and secure.

Privacy PolicyOkay, got it!

We use cookies to enhance your experience, analyse site traffic, and for marketing purposes. For more information on how we handle your personal data, please see our Privacy Policy.

Schedule a Call