Ransomware victim disclosure
← All victimsKT Group
listed as ktwhs.com · Claimed by M3Rx · listed 2 days ago
Status timeline
- ListedJun 11, 2026
- Data leakeddate unknown
At a glance
About the victim
AI dossier — public-source company profileKT Group is a Quebec-based container transport and logistics company operating in Montreal and Toronto since the 1960s. They provide local and national container distribution, warehousing, and real-time cargo tracking technology integrated with Canadian Pacific and Canadian National Rail terminals.
- Industry
- Container Transport & Logistics
- Address
- 100-230 Rue Norman, Lachine, Montreal, Quebec H8R 1A1, Canada
- Employees
- 51-200
- Founded
- 1960
Attack summary
Severity: medium — Data has been published by the threat actor, indicating confirmed exfiltration. However, the leak post provides minimal detail about data type or volume, and no proof files are enumerated. The company handles sensitive logistics and customer shipment data but the post lacks specificity about what was compromised.The m3rx group claims to have accessed KT Group's systems and has published data. No details are provided about the scope of exfiltration or encryption.
Data the group says was taken
AI dossier — extracted from the leak post- operational systems
- customer records
- business documents
What the group claims
+1 (514) 333-5402. KT Group is a leader in Quebec's transport industry, providing live information linked from all rail and port terminals since the 1960s. They offer comprehensive services including local and national container distribution, secure storage, and sufferance warehousing. Utilizing advanced technology, they provide instant updates on cargo status and delivery proof, ensuring a seamless experience for their clients. Their commitment to best-in-class service makes them a reliable choice for businesses looking to ship, store, and transport cargo efficiently. Stolen: --
The leak post
captured from the group's siteIf you are interested in this data, please contact our support.Tox: 9A1217BEDA4AB77052A25D17CB6FFB34AFA2BE462E607F2FD8E1DF1DDD4CA16A64E18B1A0BF2
Sources
Source
Indexed 2 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

