Ransomware victim disclosure
← All victimsGlobal Terminal Hizmetleri A.Ş.
listed as Global Terminal Hizmetleri A.Ş. (GTS) · Claimed by Deadlock · listed 7 days ago
Status timeline
- ListedAug 11, 2026
Current state: Listed for ransom
At a glance
- Group
- Deadlock
- Status
- Listed for ransom
- Country
- Turkey
- Sector
- Energy/Storage
- Listed on leak site
- Aug 11, 2026
About the victim
AI dossier — public-source company profileGlobal Terminal Hizmetleri A.Ş. (GTS) is the largest independent storage terminal for liquid fuels and oil in the Mediterranean region. The company operates critical energy infrastructure for fuel and oil storage and distribution.
- Industry
- Energy Storage & Liquid Fuel Terminals
Attack summary
Severity: critical — Exfiltration of 27 GB of data including PII at scale (107+ passports, 1,712+ bank statements), financial credentials, and business debt documents from critical energy infrastructure operator. Full breach threatened for publication.Deadlock claims to have exfiltrated 27 GB of data (14,836 files) from GTS. The group alleges the victim ignored contact for 72 hours and has published samples of sensitive documents including passports, bank statements, promissory notes, and financial credentials.
Data the group says was taken
AI dossier — extracted from the leak post- Passports (107, with MRZ data)
- Bank Statements (1,712, including PNB and USD accounts)
- Promissory Notes (212, relating to property debt)
- Financial Credentials (231 BIR/eFPS)
The group's post references roughly 3 sample files shown (Passport_Johnny_Tan.pdf, Holco_USD_Statement.pdf, Eton_Debt_212.pdf) proof files.
What the group claims
GTS legally registered as Global Terminal Hizmetleri A.Ş. It is the largest independent storage terminal for liquid fuels and oil in the entire Mediterranean region.
The leak post
captured from the group's sitePublishes after: <b>19d 22h 40m</b> GTS legally registered as Global Terminal Hizmetleri A.Ş. It is the largest independent storage terminal for liquid fuels and oil in the entire Mediterranean region. LT Group / Fortune Tobacco Corp Amount: 27 GB | Files: 14,836 They ignored our messages for 72 hours.. Now we publish the details of the breach. Data leaked: 107 Passports (MRZ) 1,712 Bank Statements (PNB + Holco USD accounts) 212 Promissory Notes (Eton Properties, PHP 2.53B debt) 231 BIR/eFPS credentials Samples: Passport_Johnny_Tan.pdf Holco_USD_Statement.pdf Eton_Debt_212.pdf Full leak: August 18. Contact: Session ID provided in emails. Pay for the data or pay for its permanent deletion. Otherwise, the full dump will be public. Publishes after: <b>11d 12h 51m</b> United Fiber Optic Communication Inc. (UFOC) is an established, publicly traded telecommunications company from Taiwan. The company acts as a total solution provider for communication networks and specializes in the manufacture of fiber optic cables and the provision of integrated technological systems. Ahenk Laboratuvarı is an ISO 15189-accredited medical laboratory in Turkey, founded in 1998 and located in Istanbul-Ş…
Screenshot of the leak post

Sources
Source
Indexed 7 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

