HackerFeeds
All ransomware incidents
lopay.com

Ransomware group Black X hits lopay

MEDIUM
·Financial Services·GB·2026-10-09

lopay — a financial services target operating in GB has been listed by the Black X ransomware group on 2026-10-09. The information below reflects what the threat actor has publicly claimed on their leak site; the details have not been independently verified.

Incident Report

Target Organizationlopay
Threat Group
Black X
SummaryLopay is a UK-based fintech company that provides a payment platform enabling small and medium-sized enterprises (SMEs) and sole traders to accept credit card and mobile payments, as well as manage their sales and settlements. This includes financial information belonging to client companies, such as customer payment details, card information, banking data, transaction history, and payment terminal information.
Date of Breach2026-10-09
Discovery Date2026-10-09
RegionGB
Target Domainlopay.com
Business SectorFinancial Services
Severity
MEDIUM

Claim by Black X

Lopay is a UK-based fintech company that provides a payment platform enabling small and medium-sized enterprises (SMEs) and sole traders to accept credit card and mobile payments, as well as manage their sales and settlements. This includes financial information belonging to client companies, such as customer payment details, card information, banking data, transaction history, and payment terminal information.

Posted by the Black X threat actor on its public leak site. This is the group's own statement and has not been independently verified by HackerFeeds.

Sources

Victim website

lopay.com

Leak post (onion / Tor)

tor

http://blackxppq2jvqyg4slyg3sbszv7ib2avaaycvhff5qipgdoepqi57xyd.onion/target/6ac90f73698707a00251b714

Open this URL in Tor Browser. Browsing leak sites carries real risk — view passively, never click further.

Disclaimer

HackerFeeds does not engage in the exfiltration, downloading, taking, hosting, viewing, reposting, or disclosure of any stolen information. All breach data reported here is sourced from publicly available threat intelligence feeds for awareness purposes only.