Incident analysis
RelyComply AML Platform was listed by Direwolf ransomware, a group with 147 victims recorded in this database. The listing appeared on the group's leak site on September 9, 2026.
RelyComply AML Platform is based in United Kingdom and operates in the Financial Services sector. United Kingdom ranks #4 worldwide for ransomware disclosures, with 950 victims in this database.
Sector context. Financial sector organisations are targeted for their access to funds, sensitive financial data, and the reputational damage a public breach can cause. Regulatory requirements also increase recovery costs.
Direwolf typically follows a double extortion model: data is exfiltrated from the victim's systems before files are encrypted, so the victim faces two demands at once — pay to restore access, and pay to keep stolen data unpublished. The leak site, where this listing appeared, is the lever for the second demand.