Almeida Law Group is investigating a data breach at Merge. If you believe you were affected, contact Almeida Law Group.
About Merge
Merge (merge.money) is a London-based financial technology company founded in 2020–2021 that provides B2B cross-border payment infrastructure through a single API, combining stablecoin settlement with traditional fiat payment rails. The company is regulated as an Electronic Money Institution and Virtual Asset Service Provider in France under ACPR and AMF, has approximately 30 employees, and has raised $9.5 million in seed funding from investors including Coinbase Ventures and Octopus Ventures. Because Merge is a B2B infrastructure provider rather than a consumer-facing product, any individuals affected by a security incident would likely be employees or business clients rather than retail consumers.
What Happened?
Merge was listed as an alleged victim in a ransomware claim attributed to the DireWolf group, first observed on August 10th, 2026. This is an attacker-side claim only — no independent reporting, company statement, or regulatory disclosure confirming a breach at Merge has been found. The corroborating URL included in the original source record links to a BleepingComputer article about a separate company, OnTrac, and appears to be an erroneous linkage in the underlying Ransomware.live record rather than evidence corroborating the claim against Merge. No breach date, discovery date, or notification date has been reported. The specific data types involved, if any, have not been identified; the label “Financial” in the ransomware claim reflects the attacker’s own sector categorization of the target and should not be treated as a description of exfiltrated data.
DireWolf is a financially motivated ransomware group that emerged in May 2025. Security researchers at Cyble, Trustwave SpiderLabs, and SOCRadar have documented the group’s use of double extortion tactics — encrypting victims’ systems while also threatening to publish stolen data — and its Curve25519 and ChaCha20 encryption. The group operates a Tor-based leak site and has claimed victims across manufacturing, technology, healthcare, and financial services sectors in multiple countries.
Key Facts at a Glance
- Company or Organization: Merge (merge.money)
- Industry: Financial Technology (Fintech) — B2B cross-border payment infrastructure
- Location: London, United Kingdom (regulated in France)
- Incident type: Alleged ransomware attack (unconfirmed attacker-side claim); DireWolf group
- Source: Ransomware.live attacker-side claim, first observed August 10th, 2026; supplemental research: https://cyble.com/knowledge-hub/10-new-ransomware-groups-of-2025-threat-trend-2026/, https://www.levelblue.com/blogs/spiderlabs-blog/dire-wolf-strikes-new-ransomware-group-targeting-global-sectors, https://socradar.io/blog/dark-web-profile-dire-wolf-ransomware/
What Should You Do?
Because no breach has been confirmed by Merge and no specific data types have been identified, there is no official guidance from the company at this time. As a precaution, if you are an employee or business client of Merge and are concerned about your information, you can place a fraud alert or credit freeze with the three major credit bureaus — Equifax, Experian, and TransUnion — and monitor your accounts and credit reports closely. You can request a free credit report at AnnualCreditReport.com. If you receive any identity theft protection enrollment offer from Merge, take advantage of it before any stated deadline. If you believe your information has been misused, visit IdentityTheft.gov for step-by-step guidance.
Your Legal Rights
If your personal information was involved in this breach, you may have legal rights depending on the facts of the incident and the law in your state. Almeida Law Group represents consumers in data breach and privacy litigation and can help you evaluate whether you may have a claim. Contact us at (708) 529-5418 or through our contact page for a free case evaluation.