Ransomware victim disclosure
← All victimsGanzhou Xinye Art and Craft Co., Ltd.
listed as Ganzhou Xinye Craft Co., Ltd. · Claimed by Orova · listed 6 days ago
Status timeline
- ListedAug 11, 2026
- Data leakeddate unknown
At a glance
- Group
- Orova
- Status
- Data leaked
- Country
- Hong Kong SAR China
- Sector
- Manufacturing
- Listed on leak site
- Aug 11, 2026
About the victim
AI dossier — public-source company profileGanzhou Xinye Art and Craft Co., Ltd. is a large-scale craft gift manufacturer affiliated with Xinlin Group, established in 1997. The company produces resin, glass, clay, ceramics, water globes and other handicrafts, primarily for export to the United States, Canada, Britain and other European and American markets. Total investment of $7.2 million USD.
- Industry
- Handicraft & Gift Manufacturing
- Address
- Ganzhou, China
- Founded
- 1997
Attack summary
Severity: medium — Data has been published (disclosed_status: data_published), indicating confirmed exfiltration. However, no specific data categories, volume, or sensitivity level are documented in the available post excerpt. Manufacturing/craft production typically involves trade secrets and supply chain data, but without proof inventory or detailed claims, severity cannot be elevated to 'high'.Orova claims to have accessed and published data from Ganzhou Xinye Art and Craft Co., Ltd. The specific scope of exfiltration, data types, and operational impact are not detailed in the available leak post excerpt.
What the group claims
Ganzhou Xinye Art and Craft Co., Ltd. is a large-scale craft gift production enterprise affiliated to Xinlin Group. The company was established in September 1997. It is a large foreign-owned enterprise with a total investment of 7.2 million US dollars. It mainly produces resin, glass, clay, ceramics, water globe and other handicrafts, all products are exported to the United States, Canada, Britain and other European and American countries.
Screenshot of the leak post

Sources
Source
Indexed 6 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

