Ransomware victim disclosure
← All victimsChoithrams (T. Choithram & Sons)
listed as T. Choithram And Sons, LLC · Claimed by Blacknevas · listed 11 months ago
Status timeline
- ListedOct 7, 2025
- Data leakeddate unknown
At a glance
- Group
- Blacknevas
- Status
- Data leaked
- Country
- United States
- Sector
- Consumer Services
- Listed on leak site
- Oct 7, 2025
- Data size
- 1.2 TB
- Records
- 145146 files
About the victim
AI dossier — public-source company profileChoithrams (T. Choithram & Sons) is a prominent grocery retail chain and distributor operating across the UAE, Bahrain, Qatar, and Oman, established in 1974. The company offers over 500 proprietary products including tea, spices, nuts, and grains, all HACCP-certified for food safety. It maintains an extensive logistics and distribution network serving a majority of food outlets in the region and collaborates with hundreds of major FMCG brands.
- Industry
- Grocery Retail & FMCG Distribution
- Founded
- 1974
Attack summary
Severity: critical — The group claims exfiltration of regulated PII at scale (passports for nearly all employees), sensitive corporate database contents (SQL/SAP), and additionally threatens coercion of an employee and sale of persistent network access — representing a severe, multi-dimensional compromise affecting both personal and operational data.The BlackNevas group claims to have exfiltrated a large volume of SQL and SAP data, scanned identity documents (passports) for nearly all employees, and personal documents of key IT department staff; they also claim to offer ongoing access to the corporate network and coercive cooperation from an IT employee.
Data the group says was taken
AI dossier — extracted from the leak post- SQL database dumps
- SAP data exports
- Employee passport scans
- IT department employee personal documents
- Corporate network access credentials
The group's post references roughly 1 proof file.
What the group claims
Choithrams is a prominent grocery retail chain and distributor in the UAE, Bahrain, Qatar, and Oman, established in 1974. The company offers a wide range of over 500 quality products, including tea, spices, nuts, and grains, all meeting HACCP certification for food safety. Known for its vast logistics and distribution network, Choithrams collaborates with hundreds of major FMCG brands, servicing a majority of food outlets in the region. Their commitment to trust, innovation, and sustainability has positioned them as a partner of choice in the grocery sector.As a bonus, we offer scanned documents of all key employees of the company's IT department:https://gofile.io/d/QwY56BA large volume of SQL and SAP data is also available. Passports for nearly all employees are available. We will also provide access to the corporate network and assign an IT department employee who will be forced to cooperate due to the existence of highly compromising information against them.write to us for information:[email protected]
The leak post
captured from the group's site[ Speed Group (speedgroupe.com / speedfrance.fr) is a global leader in the manufacture of synthetic monofilament lines. The company was founded in France over 40 years ago. Today, Speed Group operates four manufacturing plants located in France, the USA, Chile, and South Africa. It specializes in the extrusion of high-quality monofilaments—particularly trimmer lines—and ranks among the world's leading players in this sector. The company also produces technical monofilaments for other industries. Since 2004, it has been part of the Italian Emak Group (Tecomec). Speed Group is renowned for its high product quality, rigorous production controls, and excellent service.Cyber Attack on Speed Group (speedgroupe.com)World leader in monofilament lines manufacturing — Speed Group — has been hit by a cyber attack. Hackers breached the company’s systems and stole confidential data.More than 1 terabytes of information were exfiltrated, including technical documentation, customer databases and production data from factories in France, USA, Chile, and South Africa.The company has not issued an official statement yet. #SpeedGroup #CyberAttack #DataBreach ](http://ctyfftrjgtwdjzlgqh4avbd35sqr…
Screenshot of the leak post

Sources
Source
Indexed 11 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

