Ransomware victim disclosure
← All victimsREXT Holdings Co., Ltd.
Claimed by Ransomhouse · listed 4 days ago
Status timeline
- ListedSep 1, 2026
- Data leakeddate unknown
At a glance
- Group
- Ransomhouse
- Status
- Data leaked
- Country
- Japan
- Listed on leak site
- Sep 1, 2026
About the victim
AI dossier — public-source company profileREXT Holdings Co., Ltd. is a diversified entertainment and retail holding company based in Tokyo, Japan. The group operates multiple subsidiaries including entertainment specialty shops selling games, music, DVDs and books; a used entertainment goods resale chain; a casual apparel retailer focused on jeans; and an employment support business. They provide daily entertainment through various media channels and retail operations.
- Industry
- Entertainment & Retail (Media, Music, Games, Books, Used Goods, Apparel)
- Address
- Tokyo, Japan
Attack summary
Severity: medium — Confirmed unauthorized system access by a named ransomware group with data_published status and public company incident disclosures; however, the leak post itself is minimal and contains no specific data inventory, proof count, or explicit ransom demand. The fact that REXT issued multiple incident reports suggests operational/reputational impact, but the severity cannot be upgraded to 'high' without evidence of specific sensitive data categories (PII at scale, financial records, etc.).The ransomhouse group claims to have conducted an unauthorized system access attack against REXT Holdings. The public company disclosures (third and second reports issued August 2024) confirm a security incident, though the leak post provides minimal detail on the scope of data exfiltrated or encryption.
Data the group says was taken
AI dossier — extracted from the leak post- Company systems
- Customer or business records (type unspecified in post)
What the group claims
Private retail and holding company based in Tokyo, Japan.
Sources
Source
Indexed 4 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

