Ransomware victim disclosure
← All victimsGokals Consumer Electronics & Computers Retail
Claimed by Spacebears · listed 13 days ago
Status timeline
- Listed
May 7, 2026
Current state: Listed for ransom
At a glance
- Group
- Spacebears
- Status
- Listed for ransom
- Country
- Fiji
- Sector
- Retail
- Listed on leak site
- May 7, 2026
About the victim
AI dossier — public-source company profileGokals is described as the leading consumer electronics retailer and distributor in the South Pacific, operating in Fiji. Its product range spans small home appliances, audio-visual products, and white goods. No further details on scale or founding are publicly available from the provided sources.
- Industry
- Consumer Electronics & Appliances Retail
Attack summary
Severity: medium — Exfiltration of financial reports and databases is claimed, representing significant business data exposure; however, no proof files are published, no regulated PII or medical/government data is mentioned, no data volume is stated, and the post is a listing only.Spacebears claims to have exfiltrated financial reports, databases, and other valuable business information from Gokals, with file types including doc, docx, xls, and pdf. No encryption claim or data volume is stated, and the victim is currently listed without confirmed ransom demand.
Data the group says was taken
AI dossier — extracted from the leak post- Financial reports
- Databases
- Word documents (.doc, .docx)
- Spreadsheets (.xls)
- PDF documents
What the group claims
Leading consumer electronics retailer and distributor in the South Pacific specializing in small Home Appliances, Audio Visual products and White Goods
The leak post
captured from the group's site## Gokals Consumer Electronics & Computers Retail · Fiji **GOKALS is the leading consumer electronics retailer and distributor in the South Pacific - be it small Home Appliances; Audio Visual products or White Goods.** * _Financial reports, Data Bases and other Valuable Information_ * _doc, docx, xls, pdf... etc_
Data the group says was taken
- Financial reports
- Data Bases
- doc
- docx
- xls
Screenshot of the leak post

Sources
Source
Indexed 13 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
