Ransomware victim disclosure
← All victimsSiwax Specialties Group
Claimed by Akira · listed 3 months ago
Status timeline
- ListedMar 6, 2026
- Data leakeddate unknown
At a glance
- Group
- Akira
- Status
- Data leaked
- Country
- United States
- Listed on leak site
- Mar 6, 2026
- Data size
- 13 GB
About the victim
AI dossier — public-source company profileSiwax Specialties Group specializes in the design and production of high-quality waxes, emulsions, and hotmelts for various industries. Their product range serves sectors including packaging, food, rubber, surface treatments, and cosmetics. The company appears to have business relationships with major automotive manufacturers such as Volkswagen and Renault.
- Industry
- Specialty Waxes, Emulsions & Hotmelts Manufacturing
Attack summary
Severity: high — Confirmed exfiltration of 13 GB including employee PII (passports), financial data, NDAs, and sensitive commercial contracts with major automotive OEMs; data publication is imminent, indicating significant business and personal data exposure.Akira claims to have exfiltrated approximately 13 GB of corporate data, including employee personal identity documents (passports and scans), financial records, project files, contracts, agreements, NDAs, and files referencing Volkswagen and Renault. The group states the data will be published imminently.
Data the group says was taken
AI dossier — extracted from the leak post- Employee passports and personal identity documents
- Financial records
- Contracts and agreements
- NDAs
- Project files
- Client/partner files (Volkswagen, Renault)
What the group claims
Siwax Group specializes in the design and production of high-qual ity waxes, emulsions, and hotmelts for various industries. Their extensive product range caters to sectors such as packaging, food , rubber, surface treatments, and cosmetics. We will upload 13gb of corporate data soon. Employee personal doc uments (passports other personal docs and scans), financials, fil es with Volkswagen and Renault names and so on, projects, contrac ts and agreements, NDAs, etc.
Source
Indexed 3 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

