Ransomware victim disclosure
← All victimsUnion Trading Company W.L.L. (UTC)
listed as utc.com.kw · Claimed by LockBit · listed 3 months ago
Status timeline
- Listed
Feb 23, 2026
- Data leaked
At a glance
- Group
- LockBit
- Status
- Data leaked
- Country
- KW
- Sector
- Technology
- Listed on leak site
- Feb 23, 2026
About the victim
AI dossier — public-source company profileUnion Trading Company W.L.L. (UTC) is a leading retailer and distributor based in Kuwait, operating since 1949 with over 75 years of experience. The company runs multiple retail outlets and distribution points across Kuwait, covering divisions including electric appliances, FMCG, cosmetics and perfumes, fashion, healthcare solutions, and commercial air conditioning. UTC maintains partnerships with numerous global brands and operates several department stores and showrooms throughout Kuwait.
- Industry
- Retail & Distribution (Consumer Goods, Appliances, Cosmetics, Fashion, Healthcare)
- Address
- Dawliya Complex, Kuwait (headquarters; additional showrooms in Ahmadi, Kuwait City, Farwaniya, Salhiya, Jahra, Hawally)
- Founded
- 1949
Attack summary
Severity: high — Data has been confirmed published by LockBit, indicating successful exfiltration from a large multi-division retail and distribution company with significant business data, employee, customer, and partner records at risk.LockBit claims to have attacked UTC and the disclosure status is marked as data_published, indicating that data has been exfiltrated and subsequently published. No specific details about the volume or categories of published data were provided in the leak post.
Data the group says was taken
AI dossier — extracted from the leak post- Business data
- Retail operations data
- Brand partnership records
- Potentially employee records
- Potentially customer records
What the group claims
Union Trading Company W.L.L. (UTC) is a leading retailer and distributor in Kuwait
Sources
- Victim siteutc.com.kw
Source
Indexed 3 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
