Ransomware victim disclosure
← All victimsPT AIRFAST Indonesia
listed as airfastindonesia.com · Claimed by Warlock · listed 10 months ago
Status timeline
- ListedAug 25, 2025
- Data leakeddate unknown
At a glance
- Group
- Warlock
- Status
- Data leaked
- Country
- Indonesia
- Sector
- Transportation/Logistics
- Listed on leak site
- Aug 25, 2025
About the victim
AI dossier — public-source company profilePT AIRFAST Indonesia is an industry-leading private aviation company based in Indonesia, specializing in aircraft charter services. Their fleet includes jet aircraft (Boeing 737-8 MAX), fixed-wing turboprops (DHC-6-300/400, including amphibious variants), and rotary-wing aircraft (Airbus H125, Bell-412, MI-171). The company emphasizes safety, holding IATA ISSA and BARS certifications, and serves customers requiring chartered air transport across Indonesia.
- Industry
- Private Aviation & Aircraft Charter Services
Attack summary
Severity: medium — Data is marked as published (exfiltrated and disclosed) involving 'all user data', which implies customer/user PII exposure, but no quantified scale, no confirmed regulated data categories (medical, financial, government), and minimal detail in the leak post limits assessment to medium.The Warlock ransomware group claims to have published all user data belonging to PT AIRFAST Indonesia. The post indicates data has been disclosed, though no specific data size or ransom demand was stated.
Data the group says was taken
AI dossier — extracted from the leak post- User account data
- Customer records
- Potentially flight booking/charter data
What the group claims
all user data
Sources
- Victim siteairfastindonesia.com
Source
Indexed 10 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

