Ransomware victim disclosure
← All victimsThai Petroleum & Trading Co., Ltd.
Claimed by gunra · listed 1 month ago
Status timeline
- Listed
Apr 8, 2026
- Data leaked
At a glance
About the victim
AI dossier — public-source company profileThai Petroleum & Trading Co., Ltd. (TP&T) is a Thailand-based company operating in the petroleum and energy sector. It is engaged in the trading, distribution, and supply of petroleum products and related commodities to industrial and commercial clients. The company contributes to the regional energy supply chain within Thailand and potentially across Southeast Asia.
- Industry
- Petroleum Trading & Distribution
Attack summary
Severity: high — Data has been confirmed as published by the threat actor against an energy-sector company involved in petroleum trading, indicating successful exfiltration of potentially sensitive business and commercial data. Energy sector targeting and confirmed data publication elevate severity, though the absence of stated data volume or regulated PII evidence prevents a critical rating.The ransomware group Gunra claims to have attacked Thai Petroleum & Trading Co., Ltd. and has published data from the victim, though no specific data size or ransom amount was stated. The disclosure status indicates data has been published, suggesting exfiltration occurred.
Data the group says was taken
AI dossier — extracted from the leak post- Petroleum trading records
- Commercial client data
- Business operational documents
Original description
AI-summarised, not from the leak postThai Petroleum & Trading Co., Ltd. is a company based in Thailand operating in the petroleum and energy sector. It is involved in the trading, distribution, and supply of petroleum products and related commodities. The company serves industrial and commercial clients within Thailand and potentially across Southeast Asia. It operates within the oil and gas trading industry, contributing to the regional energy supply chain.
Sources
Source
Indexed 1 month agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
