Ransomware victim disclosure
← All victimsČili
listed as CILI · Claimed by blacknevas · listed 10 months ago
Status timeline
- Listed
Aug 6, 2025
- Data leaked
At a glance
- Group
- blacknevas
- Status
- Data leaked
- Country
- Lithuania
- Sector
- Not Found
- Listed on leak site
- Aug 6, 2025
About the victim
AI dossier — public-source company profileČili is a restaurant chain operating in Lithuania and Latvia offering diverse dining concepts including pizza restaurants, bistros, traditional Lithuanian cuisine, Chinese restaurants, coffee shops, and drive-in services. The brand operates a customer-facing mobile app and online ordering platform.
- Industry
- Food Service & Restaurants
Attack summary
Severity: critical — Confirmed exfiltration of sensitive personal data at scale including banking card information and PII from a multi-country restaurant chain's customer base, meeting the threshold for regulated/sensitive data exposure.The blacknevas group claims to have exfiltrated Čili's customer database containing personal information, addresses, email addresses, phone numbers, order history, and banking card data.
Data the group says was taken
AI dossier — extracted from the leak post- customer personal data
- physical addresses
- email addresses
- mobile phone numbers
- shopping/order history
- banking card information
What the group claims
"cili.lt" is associated with Čili, a restaurant chain that operates in Lithuania and Latvia. It started as a pizza restaurant and has since expanded into various areas, including bistros, traditional Lithuanian-style restaurants, Chinese restaurants, coffee shops, and drive-ins. The website allows users to order pizza from Čili Pizza. Additionally, there is a mobile app available for ordering, which offers exclusive discounts.In stock, the database containing customer data, addresses, mail, mobile phones, shopping history and banking card
Sources
Source
Indexed 10 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
