Ransomware victim disclosure
← All victimsYateem Group
Claimed by Blacknevas · listed 10 months ago
Status timeline
- ListedOct 29, 2025
- Data leakeddate unknown
At a glance
- Group
- Blacknevas
- Status
- Data leaked
- Country
- Bahrain
- Listed on leak site
- Oct 29, 2025
- Data size
- 1.2 TB
- Records
- 145146 files
About the victim
AI dossier — public-source company profileYateem Group is a Dubai-headquartered retail conglomerate founded in 1910, best known for its optical chain Yateem Opticians and nearly 100 optical outlets across the GCC region. The group operates multiple eyewear brands including Ateliee Optics and Sun Eye, and has diversified into premium leather boutiques and real estate management. It serves customers across the Gulf Cooperative Council countries and has insurance partnerships for vision care.
- Industry
- Optical Retail & Vision Care
- Address
- 19B St, Al Quoz Industrial Area 4, Dubai, UAE
- Founded
- 1910
Attack summary
Severity: critical — Mass exfiltration of PII at extreme scale (9M+ customer records with contact details) combined with sensitive employee data including passports and contracts constitutes a critical regulated/sensitive data breach; data is reportedly ready for publication or sale.The blacknevas group claims to have exfiltrated over 500 GB and 100,000+ files from Yateem Group, including a customer database with more than 9,000,000 records (phone numbers and emails), as well as internal employee data comprising passports, employment contracts, rights, and insurance documents; the group states negotiations have broken down and the data is being prepared for publication or sale.
Data the group says was taken
AI dossier — extracted from the leak post- Customer database (9,000,000+ records with phones and emails)
- Employee personal information
- Employee passports
- Employment contracts
- Employee rights documentation
- Insurance documents
- Internal company files
What the group claims
500+ gigabytes and over 100,000+ files availableThe Yateem Group owns nearly 100 optical outlets in addition to many other brands and facilities. At its heart, the group retains the original family values set forth by the founders.A complete customer database with all contacts has been downloaded, including phones and emails of more than 9000000+ records, as well as all internal information on YateemGroup employees, passports, rights, work contracts and insurance.The IT department is aware of the leak, but has broken off negotiations, and customer and employee data is being prepared for publication.(ready to sell all databases without publishing)access was obtained thanks to the IT departments of these companies:Trojan Construction & Holding Group www.trojan.aeT. Choithram And Sons, LLC www.choithrams.com
The leak post
captured from the group's site[ Speed Group (speedgroupe.com / speedfrance.fr) is a global leader in the manufacture of synthetic monofilament lines. The company was founded in France over 40 years ago. Today, Speed Group operates four manufacturing plants located in France, the USA, Chile, and South Africa. It specializes in the extrusion of high-quality monofilaments—particularly trimmer lines—and ranks among the world's leading players in this sector. The company also produces technical monofilaments for other industries. Since 2004, it has been part of the Italian Emak Group (Tecomec). Speed Group is renowned for its high product quality, rigorous production controls, and excellent service.Cyber Attack on Speed Group (speedgroupe.com)World leader in monofilament lines manufacturing — Speed Group — has been hit by a cyber attack. Hackers breached the company’s systems and stole confidential data.More than 1 terabytes of information were exfiltrated, including technical documentation, customer databases and production data from factories in France, USA, Chile, and South Africa.The company has not issued an official statement yet. #SpeedGroup #CyberAttack #DataBreach ](http://ctyfftrjgtwdjzlgqh4avbd35sqr…
Screenshot of the leak post

Sources
Source
Indexed 10 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

