Ransomware victim disclosure
← All victimscarducci
Claimed by Warlock · listed 1 year ago
Status timeline
- ListedJun 11, 2025
- Data leakeddate unknown
At a glance
- Group
- Warlock
- Status
- Data leaked
- Country
- South Africa
- Listed on leak site
- Jun 11, 2025
About the victim
AI dossier — public-source company profileCarducci is a South African fashion brand founded in 1978 and based in Cape Town, specializing in sophisticated menswear including tailored suits, business wear, casual clothing, accessories, and footwear. The brand is known for fine craftsmanship and refined textiles, and is part of the Seardel Group of Companies.
- Industry
- Fashion & Apparel — Menswear
- Address
- Cape Town, South Africa
- Founded
- 1978
Attack summary
Severity: medium — Data has been published by the threat actor (disclosed_status confirms 'data_published'), indicating confirmed exfiltration. However, the post excerpt provides no detail on data type, volume, or sensitivity, and no proof files are quantified. The target is a fashion/apparel company rather than a regulated sector, limiting inferred sensitivity.The Warlock group claims to have compromised Carducci and published data from the breach. No specific details on exfiltration versus encryption, or data categories, are stated in the available post excerpt.
Original description
AI-summarised, not from the leak postCarducci is an esteemed fashion brand hailing from Cape Town, South Africa. Founded in 1978, it specializes in sophisticated menswear, particularly business and casual wear, tailored suits, accessories, and footwear. The brand is renowned for its fine craftsmanship, refined textiles, and keen attention to detail. Carducci is part of the Seardel Group of Companies.
Source
Indexed 1 year agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

