Ransomware victim disclosure
← All victimsTCL Chinese Theatres
Claimed by Snatch · listed 4 years ago
Status timeline
- ListedDec 28, 2022
- Data leakeddate unknown
At a glance
- Group
- Snatch
- Status
- Data leaked
- Country
- United States
- Sector
- Media & Entertainment
- Listed on leak site
- Dec 28, 2022
About the victim
AI dossier — public-source company profileTCL Chinese Theatres (formerly Grauman's Chinese Theatre) is one of the most iconic and historic movie palaces in the world, located on Hollywood Boulevard in Los Angeles, California. The venue hosts over 50 events annually, including major film premieres, celebrity handprint and footprint imprint ceremonies, and film festivals. It remains an active cinema and tourist landmark central to Hollywood's entertainment industry.
- Industry
- Movie Theatres & Entertainment Venues
- Address
- 6925 Hollywood Blvd, Hollywood, Los Angeles, CA 90028, United States
- Employees
- 51-200
- Founded
- 1927
Attack summary
Severity: high — The disclosure status is 'data_published', meaning Snatch has confirmed exfiltration and released data. As a major entertainment venue hosting high-profile events and celebrities, the breach likely involves sensitive business, personnel, and potentially PII data. Active data publication elevates this beyond medium severity.The Snatch ransomware group claims to have attacked TCL Chinese Theatres and has published data from the breach. The post indicates data has been exfiltrated and disclosed, though the specific data types and volume are not detailed in the truncated post.
Data the group says was taken
AI dossier — extracted from the leak post- Business records
- Employee information
- Event and operational data
- Financial records
What the group claims
The TCL Chinese Theatre is the most iconic movie palace in the world. With over 50 events a year, including movie premieres, imprint ceremonies, and film festivals, the theatre continues to make Hollywood history every day.
Source
Indexed 4 years agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

