Ransomware victim disclosure
← All victimsPT Darma Henwa Tbk
Claimed by Spacebears · listed 2 months ago
Status timeline
- Listed
Mar 29, 2026
Current state: Listed for ransom
At a glance
- Group
- Spacebears
- Status
- Listed for ransom
- Country
- Indonesia
- Sector
- Mining/Construction
- Listed on leak site
- Mar 29, 2026
About the victim
AI dossier — public-source company profilePT Darma Henwa Tbk is an Indonesian publicly listed company established in 1991, specialising in mining support and excavation activities. It provides services including metal fabrication, machinery repair, and equipment leasing, as well as road, railroad, building, and civil construction. The company transitioned to a foreign investment entity in 1996 and conducted an IPO in 2007.
- Industry
- Mining Support & Civil Construction Services
- Founded
- 1991
Attack summary
Severity: high — The group claims exfiltration of a broad range of sensitive business data including employee PII, internal security reports, financial audits, and client contracts from a publicly listed mining services company, constituting significant confirmed data exposure across multiple sensitive categories.The Spacebears ransomware group claims to have exfiltrated data from PT Darma Henwa Tbk, including employee personal data, contracts, client information, financial reports, audits, project documentation, Outlook emails, and internal security reports. No encryption claim or ransom amount is stated; the post is a listing disclosure with a detailed data inventory.
Data the group says was taken
AI dossier — extracted from the leak post- Employee personal data
- Contracts and client information
- Financial reports and audits
- Projects and developments
- Outlook emails
- Internal security reports
What the group claims
Employee personal data, Contracts and client information, Financial reports and audits, Projects and developments, Outlook emails, Internal security reports
The leak post
captured from the group's siteDo you trust your data to this company? This page contains a list of companies whose clients and business partners entrusted them with their confidential data, but these companies leaked data. The data may contain confidential information such as login credentials, intellectual property, personal and financial data, etc. Operation of a network of karaoke establishments, providing leisure and entertainment services for individual and corporate clients. Development and management of a chain of food and beverage establishments, primarily in the Japanese izakaya style, as well as other concepts within the HoReCa sector. Involvement in the real estate market, including property management, leasing, and the potential development of commercial real estate assets. Operation of internet cafes that provide customers with internet access along with ancillary services such as relaxation areas, reading materials, and refreshments. AbelZeta Pharma is a global cell therapy leader focused on discovering, developing and manufacturing therapeutics to address unmet medical needs across hematologic malignancies, inflammatory and immunological diseases and solid tumors.Partners: AstraZeneca, Janssen (…
Data the group says was taken
- PII
- contracts
- financial
- emails
- security_reports
- project_data
Sources
Source
Indexed 2 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
