Skip to main content

Ransomware victim disclosure

All victims

Productos Alimenticios El Carriel S.A.S.

listed as El Carriel · Claimed by Thegentlemen · listed 5 days ago

5d
Age
since listed · data leaked

Status timeline

  1. ListedSep 7, 2026
  2. Data leakeddate unknown

At a glance

Status
Data leaked
Country
Colombia
Listed on leak site
Sep 7, 2026

About the victim

AI dossier — public-source company profile

El Carriel is a Colombian family-owned food manufacturer founded in 1992 by two brothers from Sonson, Antioquia. Starting from handmade arepas sold via bicycle consignment, the company has grown into a vertically integrated agro-industrial leader with ~70% market share in Bogotá's arepa segment, operating 9 plants, producing 1M+ arepas daily, and exporting to the US, Australia, and England. The company maintains full supply-chain control including 2,000 hectares of owned corn cultivation and its own mill.

Industry
Food Manufacturing & Distribution — Arepas, Tortillas & Corn-Based Products
Address
Bogotá & Medellín, Colombia (9 plants total)
Employees
400
Founded
1992

Attack summary

Severity: low — No operational attack is claimed. The post is a biographical/corporate profile with no stated data exfiltration, encryption, or proof files. The mention of a founder's murder is a separate criminal matter unrelated to cyber attack claims.

The leak post does not describe an operational attack (encryption or exfiltration) by the threat actor. Instead, it presents a detailed corporate profile of El Carriel as a business entity, noting the company's resilience following the November 2024 murder of co-founder Luis Alfonso Valencia at his ranch. No claim of data compromise, encryption, or extortion is stated in the disclosed material.

low

What the group claims

elcarriel.com.co Productos Alimenticios El Carriel S.A.S. Colombian family food company and dominant leader of Bogotá's arepa market (~70% share) — founded Aug 17, 1992 by two brothers from Sonson, Antioquia (Luis Alberto & Luis Alfonso Valencia) and their wives, who started selling handmade arepas from bicycles via a consignment model. Today: 9 plants in Bogotá & Medellín, 1M+ arepas/day, full vertical integration — 2,000 ha of own corn (Pioneer seeds), own mill, 400+ employees, ~$8M revenue (31.3B COP, 2023), no external investors. Exporter to the US (since 1999), Australia and England; state-recognized ESG model: 578 solar panels, 30% electric fleet. Tragedy: Nov 2024 — co-founder Luis Alfonso was murdered at his ranch by an insider who had spent 2 months profiling the property; both killers got 36 years in 2025, and the business never stopped. Bottom line: two uneducated brothers on bicycles became a vertically integrated agro-industrial champion that survived even its founder's

Sources

Source

Indexed 5 days ago

This page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.

Is this your supplier? Your competitor? You?

Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

Disclosure context

About thegentlemen

thegentlemen is a ransomware group that emerged in September 2025, operating with apparent financial motivations based on their broad targeting of commercial sectors. The group has documented 267 victims across multiple countries, with primary focus on the United States, Thailand, France, Brazil, and India. Their targeting strategy demonstrates a preference for high-value sectors including manufacturing, technology, healthcare, and financial services organizations. Given the group's recent emergence and limited public documentation from established threat intelligence sources such as CISA, FBI, or major security research firms, specific details regarding their country of origin, operational structure, attack methodologies, encryption techniques, and whether they employ ransomware-as-a-service models remain unclear. The relatively high victim count of 267 in a short operational timeframe since September 2025 suggests either an aggressive campaign pace or potential inflation of victim numbers through affiliate operations, though without corroborating intelligence reports, the group's exact operational capabilities and notable campaigns cannot be definitively established. Current intelligence indicates the group remains active as of late 2025, though comprehensive threat profiling requires additional validated reporting from authoritative cybersecurity sources. The group has been linked to 838 public disclosures across our corpus. First observed on a leak site on September 9, 2025; most recent post September 9, 2026. The operation is currently active.

Also tracked as: the gentlemen.

Timeline of this disclosure

  • September 7, 2026El Carriel listed by thegentlemen on the group's public leak site

Sector and geography

This disclosure adds to ransomware activity in the Agriculture and Food Production sector, which has 777 disclosures indexed across all operators we track. Geographically, El Carriel is reported in Colombia, a country with 20 ransomware disclosures in our corpus.

If your organisation is affected

A listing by thegentlemen means El Carriel appeared on a ransomware extortion site and data attributed to it has been published. If this is your organisation, or a supplier you depend on, the priority is to confirm the intrusion and contain it before the window to act closes.

  • Engage your incident-response team and preserve forensic evidence before remediating — do not wipe affected systems first.
  • Force a password reset and revoke active sessions for exposed accounts; rotate any credentials, API keys or certificates that may have been in the stolen data.
  • Assess regulatory notification duties (GDPR, NIS2, sector regulators) — many carry a 72-hour reporting clock from awareness.
  • Monitor for the data appearing on thegentlemen's leak site and across paste and breach channels, and brief downstream partners who may be exposed through you.

How we know this. Darkfield monitors public ransomware leak sites continuously, archiving every new disclosure and the data later released against the victim. Each entry on this page is sourced from the operator's own publication and cross-checked against complementary OSINT feeds (RansomLook, ransomware.live, RansomWatch). We do not collect or host stolen data — only the metadata, timestamps and screenshots needed to make the public disclosure searchable and accountable. Records here are corrected when the original post is edited, retracted, or merged with another disclosure.