Ransomware victim disclosure
← All victimscgcsa.co.za
Claimed by stormous · listed 18 days ago
Status timeline
- Listed
May 3, 2026
- Data leaked
At a glance
- Group
- stormous
- Status
- Data leaked
- Country
- ZA
- Sector
- Business Services
- Listed on leak site
- May 3, 2026
About the victim
AI dossier — public-source company profileThe Consumer Goods Council of South Africa (CGCSA) is an industry association headquartered in South Africa representing over 9,000 member companies across the Consumer Goods, Retail, and Services sectors. It provides advocacy, global standards (including GS1 barcoding), food safety, crime risk management, regulatory advisory, and skills development services. It is one of the largest employer-sector representative bodies in South Africa.
- Industry
- Consumer Goods & Retail Industry Association
- Address
- South Africa (specific street address not stated on public site)
Attack summary
Severity: critical — The group claims confirmed exfiltration of PII at scale (151,000+ documents), payroll and tax records, financial accounting data, and sensitive partnership/supply-chain data involving major global FMCG companies, all of which constitute regulated and highly sensitive data categories affecting thousands of member organisations and individuals.The Stormous ransomware group claims to have exfiltrated a broad range of data from CGCSA, including over 151,000 sensitive documents from the CRM database, full Sage 200 Evolution backups with payroll and tax records, complete PII of staff and executives, and full access to GS1 South Africa SharePoint data including partnership information with global entities such as Unilever, Nestlé, and L'Oréal.
Data the group says was taken
AI dossier — extracted from the leak post- Vendor and corporate data (names, emails, phone numbers)
- Financial accounting records
- Sales order reports
- SQL Server database systems
- Sage 200 Evolution SQL backups (full, including transaction history)
- Tax records
- Payroll data
- CRM database (151,000+ documents, contracts, internal communications)
- Legal archives
- GS1 South Africa SharePoint data
- GDSN protocols and partnership data
- PII of administrative staff and executives (private emails, mobile numbers)
What the group claims
endor & Corporate Data ( Name-Email-Numbers/PMS NAME ), Financial Accounting Records , sales Order Reports , Database Systems , SQL Server , Sage 200 Evolutuion SQL, operational Security Data، Full Sage 200 Evolution backups including all transaction history, tax records, and payroll.CRM & Legal Archives Over 151,000 sensitive documents, contracts, and internal communications from the CRM database.Full access to GS1 South Africa SharePoint, including GDSN protocols and partnership data with global entities like Unilever, Nestle, and L'Oreal.Complete PII (Personally Identifiable Information) of administrative staff and executive members, including private emails and mobile numbers.
Sources
- Victim sitecgcsa.co.za
Source
Indexed 18 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
