Ransomware victim disclosure
← All victimsSea Island Shrimp House
listed as www.shrimphouse.com · Claimed by INC Ransom · listed 5 months ago
Status timeline
- ListedJan 26, 2026
- Data leakeddate unknown
At a glance
- Group
- INC Ransom
- Status
- Data leaked
- Country
- United States
- Sector
- Hospitality and Tourism
- Listed on leak site
- Jan 26, 2026
- Data size
- 1 TB
About the victim
AI dossier — public-source company profileSea Island Shrimp House is a family-owned seafood restaurant chain founded in 1965, operating seven locations across San Antonio and New Braunfels, Texas. The company specializes in affordable, high-quality seafood including fried and grilled fish, shrimp, oysters, and seafood boils. It offers dine-in, carry-out, curbside, and delivery services along with a loyalty rewards program.
- Industry
- Casual Dining / Seafood Restaurants
- Address
- San Antonio & New Braunfels, Texas, United States
- Founded
- 1965
Attack summary
Severity: high — 1 TB of data is claimed exfiltrated and published by INC Ransom, a prolific group known for large-scale data theft. Even for a restaurant chain, this volume likely encompasses customer PII (loyalty program members, payment records), employee records, and business financials. The disclosed/published status confirms data was released publicly.INC Ransom claims to have exfiltrated approximately 1 TB of data from Sea Island Shrimp House and has published the data. No details on specific data categories or encryption were provided in the leak post.
Data the group says was taken
AI dossier — extracted from the leak post- 1 TB of unspecified company data
What the group claims
1tb data
Sources
- Victim sitewww.shrimphouse.com
Source
Indexed 5 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

