Ransomware victim disclosure
← All victimsEuro Creations
Claimed by Thegentlemen · listed 2 months ago
Status timeline
- ListedApr 23, 2026
- Data leakeddate unknown
At a glance
- Group
- Thegentlemen
- Status
- Data leaked
- Country
- Thailand
- Sector
- Consumer Services
- Listed on leak site
- Apr 23, 2026
About the victim
AI dossier — public-source company profileEuro Creations (SET: EURO) is a Thailand-based publicly listed company headquartered on Sukhumvit Road, Bangkok, specializing in importing and distributing European luxury furniture, lighting, and home accessories. The company operates three flagship showrooms in prime Bangkok locations — CDC, Siam Paragon, and Thonglor — carrying world-renowned brands such as Cassina, Molteni&C, Poltrona Frau, and Rolf Benz.
- Industry
- Luxury Furniture & Home Accessories Retail
- Address
- Sukhumvit Road, Bangkok, Thailand
- Founded
- 1996
Attack summary
Severity: medium — Data is marked as published, confirming some level of exfiltration, but no specific data types, volume, or regulated/sensitive data (PII, financial, medical) are described in the leak post, and no proof file count is provided.The group thegentlemen has disclosed data from Euro Creations with status marked as 'data_published', indicating exfiltration and publication of company data; no specific ransom demand or data volume was stated in the leak post.
What the group claims
eurocreations.co.th Luxury furniture retailer founded in 1996, Bangkok — Euro Creations is a Thailand-based public company (SET: EURO) specializing in importing and distributing European luxury furniture, lighting, and home accessories, headquartered on Sukhumvit Road, Bangkok. Three flagship stores in prime Bangkok locations — The company operates showrooms at CDC, Siam Paragon, and Thonglor, offering curated collections from world-renowned European brands across living room, bedroom, bathroom, kitchen, outdoor, and wardrobe categories.
Sources
- Victim siteeurocreations.co.th
Source
Indexed 2 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

