Menu
Browse

The Icon Group

Primary URL Location Industry
www[.]theicongroup[.]net
Country Thailand
Financial Services Icon
Financial Services
Profile

TheIcon Group, also known by its alias, is a company headquartered in Thailand. The organization’s activities involve the collection and storage of customer identification and financial information, as indicated by the types of data compromised in a 2022 breach. This includes personal details such as full names, national identification numbers, bank account information, addresses, and contact details. The company also maintains extensive know‑your‑customer (KYC) documentation, including copies of identity cards and bank books.

On October 2, 2022, The Icon Group was targeted by the cybercriminal group DESORDEN. The attackers exfiltrated approximately 161 gigabytes of databases and files from the company’s systems. The stolen data comprised the aforementioned personal and financial information, along with roughly 70,000 individual KYC records. DESORDEN asserted that they had maintained prolonged unauthorized access to the organization’s network prior to the data theft. The group subsequently released samples of the stolen information on public platforms to validate their claim. The volume and sensitivity of the data highlight the scale of the information assets held by The Icon Group.

Despite the public disclosure by DESORDEN, The Icon Group did not issue an official acknowledgment of the breach at the time of reporting. The company also did not confirm whether it had notified relevant regulators or affected individuals about the incident. This lack of public response left the extent of any remedial actions or customer notifications unclear. The incident underscores the risks associated with storing large volumes of sensitive personal and financial data. It also illustrates the potential consequences when threat actors achieve sustained access to corporate networks.

As of the information available, no further details regarding The Icon Group’s corporate structure, ownership, or subsidiaries have been disclosed in the source material. The organization's primary known footprint remains its operation in Thailand and its handling of KYC and financial data. The 2022 breach serves as the principal publicly documented event shaping the current understanding of the company’s profile.

Incidents
Linked incidents available to members
1 incident