Ransomware victim disclosure
← All victimsPort of Tanjung Pelepas
Claimed by Direwolf · listed 2 days ago
Status timeline
- ListedSep 11, 2026
- Data leakeddate unknown
At a glance
- Group
- Direwolf
- Status
- Data leaked
- Country
- Malaysia
- Sector
- Transportation
- Listed on leak site
- Sep 11, 2026
About the victim
AI dossier — public-source company profilePort of Tanjung Pelepas is a major container and general cargo port operator located in Malaysia. The port serves regional and international shipping routes as a key maritime transportation hub.
- Industry
- Marine Shipping & Transportation
Attack summary
Severity: high — Large-scale data exfiltration (200 GB) from critical maritime infrastructure with operational, financial, and customer data at risk. Port operations are critical infrastructure; exposure of shipping records and customer data poses significant business and operational risk.The direwolf group claims to have exfiltrated approximately 200 GB of data from Port of Tanjung Pelepas. The group has published the victim listing with a data inventory but has not published proof files or detailed breach documentation.
Data the group says was taken
AI dossier — extracted from the leak post- operational records
- shipping documentation
- employee records
- financial data
- customer information
What the group claims
Marine Shipping & Transportation
The leak post
captured from the group's site```
{"article":{"id":135,"title":"Port of Tanjung Pelepas","content":"","content_format":"markdown","summary":"{\"company_name\":\"Port of Tanjung Pelepas\",\"company_website\":\"https://www.ptp.com.my\",\"industry\":\"Marine Shipping \\u0026amp; Transportation\",\"gdpr_restricted\":false,\"data_size\":\"200G\"}","country":"MY","file_browser_url":"","data_types":"20,25,30","countdown_end":"2026-09-30T15:39:00Z","status":"","view_count":0,"publish_time":"2026-09-11T15:42:01.231Z","created_at":"2026-09-11T15:39:55.329403366Z","updated_at":"2026-09-11T15:42:01.385709306Z"}}
```Sources
Source
Indexed 2 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

