Ransomware victim disclosure
← All victimsXtera
Claimed by Snatch · listed 4 years ago
Status timeline
- ListedMar 8, 2022
- Data leakeddate unknown
At a glance
- Group
- Snatch
- Status
- Data leaked
- Country
- United States
- Sector
- Manufacturing
- Listed on leak site
- Mar 8, 2022
About the victim
AI dossier — public-source company profileXtera is a US-based company specialising in submarine cable solutions, focused on maximising optical capacity and capability from seabed to city. The company leverages deep expertise, proprietary technology, and leading-edge research and development to deliver undersea communications infrastructure. Xtera operates in a technically specialised segment of the global telecommunications and undersea cable market.
- Industry
- Submarine Cable & Optical Telecommunications Infrastructure
- Employees
- 51-200
Attack summary
Severity: high — Data has been confirmed published by the threat actor. Xtera operates in submarine cable and optical telecommunications infrastructure — a sector with national security and critical infrastructure implications. Exfiltration of R&D and technical data from such a company represents significant business and potentially strategic risk, warranting a high severity rating even without precise data volume figures.The Snatch ransomware group claims to have compromised Xtera and has published data (disclosed status: data_published), indicating exfiltration of company data. No ransom amount or specific data volume has been stated in the post.
Data the group says was taken
AI dossier — extracted from the leak post- Internal business documents
- Research and development files
- Technical engineering data
- Proprietary telecommunications technology data
What the group claims
Xtera deliver submarine cable solutions that maximise optical capacity and capability from seabed to city through outstanding expertise, know-how and technology innovation that is underpinned by leading-edge research and development.
Source
Indexed 4 years agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

