Ransomware victim disclosure
← All victimsITC Properties Group Limited
Claimed by Orova · listed 2 days ago
Status timeline
- ListedAug 29, 2026
- Data leakeddate unknown
At a glance
- Group
- Orova
- Status
- Data leaked
- Country
- Hong Kong SAR China
- Listed on leak site
- Aug 29, 2026
About the victim
AI dossier — public-source company profileITC Properties Group Limited is a Hong Kong-based property company. Limited public information is available from the clearnet domain provided.
- Industry
- Real Estate & Property Development
Attack summary
Severity: critical — Confirmed exfiltration of highly sensitive regulated data including identity documents (HKID, passports), financial records (bank statements, audit statements, treasury data), and personal employee information (medical records, payroll). The breadth and depth of data categories — especially identity documents and medical records — combined with Hong Kong regulatory context elevates this to critical severity.Orova claims to have exfiltrated a comprehensive set of financial, corporate, legal, and personnel records from ITC Properties Group Limited. The group has published a detailed inventory of stolen data categories but the leak post does not specify a ransom demand or provide proof file counts.
Data the group says was taken
AI dossier — extracted from the leak post- Financial statements and audit records
- Treasury and management accounts
- Bank statements and loan summaries
- M&A and acquisition documentation
- Board minutes and corporate resolutions
- Shareholder records
- Legal agreements and contracts
- HKID and passport copies
- Payroll and salary information
- Employee medical and HR records
- IT infrastructure configuration
- Subsidiary corporate records
What the group claims
ITC Properties is an investment holding company and the Group is principally engaged in development of, selling of and investment in properties in Macau, Hong Kong, the People's Republic of China (the "PRC") and Canada; securities investments and provision of loan financing services.
The leak post
captured from the group's site5 Days 10 Hours 32 Minutes 30 Seconds 1. Highest priority: unpublished financial and treasury data Management Account, Audit Financial Statement, Loan Summary, Bank Statement, Cashflow, Tax Computation, Profits Tax, Financial Support, Bank Facility, Securities Accounts 2. Acquisition, disposal, investment and M&A information Acquisition, Disposal, Subscription, SPA, Sale and Purchase Agreement, Due Diligence, Valuation, Share Mortgage, Convertible Bonds, Investment Policy, Project Files 3. Board, directors and corporate-secretarial records Board Minutes, Minutes of Directors Meeting, Minutes of General Meeting, Directors' Resolution, Shareholders' Resolution, Special Resolution, Register of Directors, Register of Secretaries, Statutory Records 4. Legal documents, contracts and litigation Agreement, Funding Agreement, Loan Agreement, S&P Agreement, Subordination Agreement, Share Mortgage, Construction Contract, Employment Agreement, Legal Opinion, Confidentiality Undertaking, NDA-related material 5. Internal audit, compliance and control findings 6. HKID, passports and identity documents 7. Employee salary, payroll, medical and HR information Payroll, Salary Spreadsheet, Salar…
Screenshot of the leak post

Sources
Source
Indexed 2 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

