Ransomware victim disclosure
← All victimsMegaCorp One
Claimed by la_piovra · listed 3 years ago
Status timeline
- Listed
Jun 10, 2023
- Data leaked
At a glance
- Group
- la_piovra
- Status
- Data leaked
- Country
- United States
- Sector
- Technology
- Listed on leak site
- Jun 10, 2023
About the victim
AI dossier — public-source company profileMegaCorp One is a technology company based in the United States. No public site content was available to provide further detail on its operations, scale, or specific products and services.
- Industry
- Technology
Attack summary
Severity: high — The group claims both encryption and exfiltration of proprietary data, and the data has a stated imminent release timeline. However, no regulated/sensitive data (PII, medical, financial) is confirmed, and no proof files have been published yet, preventing a critical rating.The group claims to have exploited a vulnerability discovered via publicly accessible GitHub-hosted website code to encrypt the victim's files, and states it has also exfiltrated proprietary data which it threatens to release within two days if payment is not made.
Data the group says was taken
AI dossier — extracted from the leak post- Encrypted files (full filesystem or website files)
- Proprietary business data (exfiltrated, unreleased)
What the group claims
In case you were wondering how we did it, your entire website code is on github!!!! A look on the code, a vuln here and there, and voila, all your files are now encrypted. We will start releasing other proprietary data that we copied. You have 2 days to pay!
Sources
Source
Indexed 3 years agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
