Key Takeaways
- N0n claims it accessed core systems and sensitive investor-related information at Argentem Creek Partners.
- The listing remains a threat-actor allegation, but reported network disruption raises operational and disclosure concerns.
- The incident reflects ransomware groups’ growing emphasis on data theft, business interruption, and layered extortion.
Ransomware.live has listed US-based private credit investment firm Argentem Creek Partners as a victim of the emerging N0n ransomware group, placing the investment manager at the center of an extortion claim involving potentially sensitive corporate and investor data.
N0n claims to possess "full corporate network evidence" from Argentem Creek Partners. The material allegedly includes information associated with Active Directory, SharePoint, managed service provider tooling, and tax-season investor document flows. The group also claims that corporate connectivity remains severed pending a settlement.
Those statements come from the threat actor and should not be treated as independent confirmation of the scope, cause, or impact of the incident. No evidence in the available reporting establishes how N0n obtained access, when the intrusion began, whether files were encrypted, or how much information may have been removed. The amount of any ransom demand has not been disclosed.
Still, the claimed access is significant. Active Directory can provide control over identities and permissions across a corporate environment, while SharePoint commonly contains internal records, transaction materials, and collaborative documents. MSP tooling can widen the investigation because it may have privileged access to multiple systems. Investor document workflows add another layer, particularly when they include tax records, contact information, account details, or confidential fund communications.
Financial firms do not need to be large consumer banks to attract extortion groups. Private credit managers handle data that can carry substantial regulatory, commercial, and reputational sensitivity. Attackers may view that information as leverage even when an organization can restore encrypted systems from backups.
That appears consistent with a broader move toward double and triple extortion. Rather than relying solely on encryption, ransomware groups may steal files, interrupt operations, threaten publication, and contact customers or business partners. In some incidents, the theft itself becomes the product. Why spend time encrypting every endpoint if confidential financial documents provide enough pressure?
The wider threat environment supports that concern. ENISA identified ransomware as Europe's most impactful cyber threat in its Threat Landscape 2025 report. The report found that ransomware accounted for roughly 83.5% of malicious code deployed after attackers gained access and appeared in more than 80% of cybercrime incidents affecting EU organizations.
A Security Affairs review of ENISA's findings similarly highlights the persistence of ransomware across the reporting period. Separately, Breachsense's State of Ransomware 2025 reported that 7,307 organizations appeared on ransomware leak sites during 2025, an increase of 45% from 2024. It identified 138 active groups and found that more than half of listed victims were based in the US.
Other research points to changing intrusion patterns. Verizon's 2025 Data Breach Investigations Report found ransomware in 44% of analyzed breaches and 88% of breaches involving small and midsize businesses. Sophos reported that exploited vulnerabilities were the initial entry point in 32% of ransomware incidents, while data-theft-only attacks tripled to 12% of cases.
For Argentem Creek Partners, the immediate priorities are likely to include isolating affected infrastructure, preserving forensic evidence, rotating privileged credentials, and determining whether data left the environment. Investigators would also typically examine cloud audit logs, identity changes, remote-management activity, and access involving third-party service providers.
Containment is only part of the job. Argentem Creek Partners may also need to assess contractual obligations, investor notifications, insurance requirements, and applicable breach-reporting rules. The NIST Cybersecurity Framework, updated in 2024, and NIST SP 800-61 Rev.2 offer established structures for organizing incident response, recovery, and communication.
CrowdStrike, Palo Alto Networks, SentinelOne, and other security vendors operate in this defensive market, but tooling alone does not settle an incident. Identity controls, vulnerability remediation, tested recovery procedures, and careful third-party oversight all shape the outcome. For private investment firms, rehearsing how to communicate with investors can be just as important as restoring servers. N0n's allegation against Argentem Creek Partners is still unverified in key respects, yet it illustrates how quickly an intrusion claim can become an operational, legal, and investor-relations event.
⬇️