Ransomware victim disclosure
← All victimsSTARS Alliance
listed as starsalliance.com · Claimed by Warlock · listed 1 year ago
Status timeline
- ListedAug 17, 2025
- Data leakeddate unknown
At a glance
- Group
- Warlock
- Status
- Data leaked
- Country
- United States
- Listed on leak site
- Aug 17, 2025
About the victim
AI dossier — public-source company profileSTARS Alliance is a procurement and operational cooperation consortium of nuclear power plant operators in the United States, primarily in Nuclear Regulatory Commission Region IV. The alliance enables smaller nuclear station operators to achieve economies of scale and cost advantages through group purchasing power and collective focus on safety, reliability, and performance improvements.
- Industry
- Nuclear Energy & Power Generation
Attack summary
Severity: high — Potential exfiltration of sensitive operational and procurement data from critical nuclear infrastructure operators. The involvement of nuclear power plants and their supply chain information represents significant national security and public safety concern, even without explicit proof files shown.The ransom group 'Warlock' claims to have exfiltrated data from STARS Alliance. The post indicates the data has been purchased by other buyers, suggesting the threat actor no longer possesses exclusive access to the compromised information.
Data the group says was taken
AI dossier — extracted from the leak post- Procurement contracts
- Supplier agreements
- Operational performance data
- Nuclear facility information
What the group claims
The data has been purchased by other buyers
Sources
- Victim sitestarsalliance.com
Source
Indexed 1 year agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

