Ransomware victim disclosure
← All victims安徽省交通规划设计研究总院股份有限公司 (Anhui Province Traffic Planning & Design Research Institute Co., Ltd.)
listed as atcdi.com.cn · Claimed by Lockbit3 · listed 2 years ago
Status timeline
- ListedJul 31, 2024
- Data leakeddate unknown
At a glance
- Group
- Lockbit3
- Status
- Data leaked
- Country
- China
- Sector
- Technology
- Listed on leak site
- Jul 31, 2024
About the victim
AI dossier — public-source company profileAnhui Province Traffic Planning & Design Research Institute (ATCDI) is a state-owned enterprise engaged in transportation infrastructure planning, design, and engineering consulting. Based in Hefei, China, the company provides services across road engineering, bridge design, rail transit, water conservancy, municipal, aviation, and civil engineering projects.
- Industry
- Transportation & Infrastructure Planning & Design
- Address
- 安徽省合肥市高新区彩虹路1008号 (1008 Caihong Road, High-Tech Zone, Hefei, Anhui Province, China)
Attack summary
Severity: medium — Confirmed data publication by ransomware group with access to sensitive infrastructure planning and engineering data. No explicit confirmation of PII at scale or critical operational disruption, but compromised infrastructure design data poses moderate risk. Data size and specific proof volume not quantified.LockBit3 claims to have compromised ATCDI and published exfiltrated data. The group references a completed water supply project (Kapari Water Supply Project) as context, indicating access to operational and project documentation.
Data the group says was taken
AI dossier — extracted from the leak post- Project designs and engineering documentation
- Infrastructure planning records
- Water supply project details
- Operational records
- Corporate communications
What the group claims
The Kapari Water Supply Project, successfully implemented by ATCDI, brings clean water access to the remote Kapari Village in Abau District, Central Province.
Sources
Source
Indexed 2 years agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

