Ransomware victim disclosure
← All victimsWinnitex (Americas) Limited
Claimed by Ransomhouse · listed 13 days ago
Status timeline
- Listed
May 7, 2026
- Data leaked
At a glance
- Group
- Ransomhouse
- Status
- Data leaked
- Country
- Canada
- Sector
- textiles
- Listed on leak site
- May 7, 2026
- Data size
- 743 GB
- Ransom demanded
- $740
About the victim
AI dossier — public-source company profileWinnitex (Americas) Limited is a global woven fabric manufacturer and trader, founded in 1964 in Hong Kong as a commission dyeing house. The company produces and trades yarns, garment fabrics, and finished textile goods, with manufacturing operations including a wholly-owned subsidiary in mainland China (Zhejiang Qing Mao Weaving, Dyeing & Printing Co., Ltd.). It serves apparel, workwear, and uniform brands worldwide and reported HK$740 million in revenue from textile sales in 2024.
- Industry
- Textile Manufacturing & Trading (Woven Fabrics)
- Employees
- 50
- Founded
- 1964
Attack summary
Severity: high — 743 GB of data is confirmed exfiltrated and published, representing significant business data including supplier, customer, and financial records from a multi-national textile trading and manufacturing operation. No evidence of regulated personal medical or government data, keeping this below critical.RansomHouse claims to have encrypted systems at Winnitex (Americas) Limited, with a disclosed data volume of 743 GB at stake. The post status is 'data_published', indicating exfiltrated data has been or is being released; the ransom demand noted is $740.
Data the group says was taken
AI dossier — extracted from the leak post- Business financial records
- Textile product trading data
- Supplier and customer records
- Manufacturing and production data
- Corporate subsidiary information
What the group claims
Winnitex (Americas) Limited is primarily engaged in the trading of textile products, including yarns, garment fabrics, and finished textile goods.
The leak post
captured from the group's site```
{"data":[{"id":"a1894b76b7004c75a3a0845799af49956592e3d9","display":"animated","header":"HOT NEWS","info":" Trellix is a global cybersecurity company.","url":"","sort":1,"views":"436242"},{"id":"336b257f582b17573c97578efd4b22762bf77344","sort":2,"header":"Trellix (McAfee & FireEye)","url":"https://www.trellix.com/","private":"false","revenue":"1.5-2 B$","employees":"5000","info":"Trellix is a global cybersecurity company formed from the October 2021 merger of McAfee Enterprise and FireEye. It provides services to over 50,000 business and government customers worldwide, protecting more than 200 million endpoints. The companys open and native extended detection and response (XDR) platform helps organizations confronted by todays most advanced threats gain confidence in the protection and resilience of their operations. Trellix, along with an extensive partner ecosystem, accelerates technology innovation through machine learning and automation to empower over 40,000 business and government customers with living security","statusDate":"DEPENDS ON YOU","status":"EVIDENCE","published":"NOT YET","action":"Encrypted","actionDate":"17/04/2026","volume":"~","content":"cybersecurity.html"…Sources
Source
Indexed 13 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
