Ransomware victim disclosure
← All victimsSunway Berhad
Claimed by Qilin · listed 7 days ago
Status timeline
- ListedJul 23, 2026
- Data leakeddate unknown
At a glance
- Group
- Qilin
- Status
- Data leaked
- Country
- Malaysia
- Sector
- Hospitality and Tourism
- Listed on leak site
- Jul 23, 2026
About the victim
AI dossier — public-source company profileSunway Berhad is one of Southeast Asia's leading conglomerates with diverse business divisions including real estate development, private healthcare, construction, hotel operations, leisure parks, retail malls, and trading & manufacturing. Headquartered in Malaysia, the group operates as a master community developer with a focus on integrated sustainable townships and ESG-aligned business practices.
- Industry
- Conglomerate: Real Estate, Healthcare, Construction, Hospitality, Leisure, Retail
Attack summary
Severity: medium — Data has been published by the group (disclosed_status = data_published) and Sunway Berhad is a major conglomerate likely to hold sensitive business and customer data; however, without visibility into the leak post content or proof inventory, the specific data types and volume cannot be confirmed. The severity is elevated above 'low' due to confirmed publication but cannot be raised to 'high' or 'critical' without evidence of regulated/sensitive data exfiltration.The qilin ransomware group claims to have attacked Sunway Berhad and published data from the breach. No specific details of the attack method (encryption vs. exfiltration) or data categories are provided in the available leak post excerpt.
What the group claims
N/A
Sources
Source
Indexed 7 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

