Ransomware victim disclosure
← All victimsČili
listed as CILI · Claimed by Blacknevas · listed 1 year ago
Status timeline
- ListedAug 6, 2025
- Data leakeddate unknown
At a glance
- Group
- Blacknevas
- Status
- Data leaked
- Country
- Lithuania
- Listed on leak site
- Aug 6, 2025
- Data size
- 1.2 TB
- Records
- 145146 files
About the victim
AI dossier — public-source company profileČili is a restaurant chain operating in Lithuania and Latvia offering diverse dining concepts including pizza restaurants, bistros, traditional Lithuanian cuisine, Chinese restaurants, coffee shops, and drive-in services. The brand operates a customer-facing mobile app and online ordering platform.
- Industry
- Food Service & Restaurants
Attack summary
Severity: critical — Confirmed exfiltration of sensitive personal data at scale including banking card information and PII from a multi-country restaurant chain's customer base, meeting the threshold for regulated/sensitive data exposure.The blacknevas group claims to have exfiltrated Čili's customer database containing personal information, addresses, email addresses, phone numbers, order history, and banking card data.
Data the group says was taken
AI dossier — extracted from the leak post- customer personal data
- physical addresses
- email addresses
- mobile phone numbers
- shopping/order history
- banking card information
What the group claims
"cili.lt" is associated with Čili, a restaurant chain that operates in Lithuania and Latvia. It started as a pizza restaurant and has since expanded into various areas, including bistros, traditional Lithuanian-style restaurants, Chinese restaurants, coffee shops, and drive-ins. The website allows users to order pizza from Čili Pizza. Additionally, there is a mobile app available for ordering, which offers exclusive discounts.In stock, the database containing customer data, addresses, mail, mobile phones, shopping history and banking card
The leak post
captured from the group's site[ Speed Group (speedgroupe.com / speedfrance.fr) is a global leader in the manufacture of synthetic monofilament lines. The company was founded in France over 40 years ago. Today, Speed Group operates four manufacturing plants located in France, the USA, Chile, and South Africa. It specializes in the extrusion of high-quality monofilaments—particularly trimmer lines—and ranks among the world's leading players in this sector. The company also produces technical monofilaments for other industries. Since 2004, it has been part of the Italian Emak Group (Tecomec). Speed Group is renowned for its high product quality, rigorous production controls, and excellent service.Cyber Attack on Speed Group (speedgroupe.com)World leader in monofilament lines manufacturing — Speed Group — has been hit by a cyber attack. Hackers breached the company’s systems and stole confidential data.More than 1 terabytes of information were exfiltrated, including technical documentation, customer databases and production data from factories in France, USA, Chile, and South Africa.The company has not issued an official statement yet. #SpeedGroup #CyberAttack #DataBreach ](http://ctyfftrjgtwdjzlgqh4avbd35sqr…
Screenshot of the leak post

Sources
Source
Indexed 1 year agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

