Ransomware victim disclosure
← All victimsOceanFish
listed as Ocean Fish · Claimed by Akira · listed 5 months ago
Status timeline
- ListedJan 22, 2026
- Data leakeddate unknown
At a glance
- Group
- Akira
- Status
- Data leaked
- Country
- United Kingdom
- Listed on leak site
- Jan 22, 2026
- Data size
- 10 GB
About the victim
AI dossier — public-source company profileOceanFish is a Romanian company founded in 1998 specialising in the import, processing, and distribution of fish products, including fresh, frozen, prepared seafood, sushi, and canned goods. The company primarily serves the HORECA (hotel, restaurant, catering) sector. It is described as a leading player in its segment within Romania.
- Industry
- Seafood Import, Processing & Distribution
- Address
- Romania
- Founded
- 1998
Attack summary
Severity: high — Confirmed exfiltration of 10 GB of data including employee PII, financial and payment details, and confidential business records constitutes significant data exposure across multiple sensitive categories, warranting a high severity rating.Akira claims to have exfiltrated approximately 10 GB of corporate data from OceanFish, encompassing employee personal information, financial records, payment details, project files, partner information, and other internal confidential files, with publication described as imminent.
Data the group says was taken
AI dossier — extracted from the leak post- Employee personal information
- Financial records
- Payment details
- Project files
- Partner information
- Internal confidential files
What the group claims
OceanFish is a leading company in Romania since 1998, specializin g in the import, processing, and distribution of fish products. T heir offerings include fresh, frozen, prepared seafood, sushi, an d canned products, catering primarily to the HORECA sector We will upload 10gb of corporate data soon.Employee personal info rmation, financials, payment details, project files, partners inf o, internal confidential files and so on.
Source
Indexed 5 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

