Ransomware victim disclosure
← All victimsAll Cosmos Bio-Tech (ACBT)
listed as PT All Cosmos Biotek · Claimed by Gunra · listed 3 days ago
Status timeline
- ListedAug 5, 2026
- Data leakeddate unknown
At a glance
- Group
- Gunra
- Status
- Data leaked
- Country
- Indonesia
- Sector
- Healthcare
- Listed on leak site
- Aug 5, 2026
About the victim
AI dossier — public-source company profileAll Cosmos Bio-Tech (ACBT) is a Malaysia-based investment holding company established by Taiwanese investors and listed on Taiwan's main board. Through subsidiary All Cosmos Industries Sdn Bhd, it operates across four major sectors: agricultural biochemical fertilizers, healthcare & pharmaceuticals, waste reutilization, and microbial research & development.
- Industry
- Agricultural Biotechnology, Biochemical Fertilizers & Pharmaceuticals
- Address
- PLO 650, Jalan Keluli 7, Pasir Gudang Industrial Estate, 81700 Pasir Gudang, Johor, Malaysia
- Founded
- 1999
Attack summary
Severity: medium — Data exfiltration confirmed by disclosure status ('data_published'), but no proof files are advertised in the available post excerpt, no specific sensitive data categories are detailed, and the post lacks operational impact claims. The company handles pharmaceuticals and healthcare data which elevates concern, but evidence of actual sensitive data exposure is not explicit in the provided post.The gunra group claims to have exfiltrated data from ACBT. No specific details are provided regarding the scope of data accessed, encryption status, or operational disruption.
What the group claims
Sector: Agricultural Biotechnology & Fertilizer | Revenue: US$ 5,000,000
Sources
- Victim siteallcosmos.com
Source
Indexed 3 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

