Ransomware victim disclosure
← All victimsWoflow, Inc.
Claimed by Shinyhunters · listed 3 months ago
Status timeline
- ListedMar 3, 2026
- Data leakeddate unknown
At a glance
- Group
- Shinyhunters
- Status
- Data leaked
- Country
- United States
- Sector
- Technology
- Listed on leak site
- Mar 3, 2026
About the victim
AI dossier — public-source company profileWoflow, Inc. is a US-based technology company specializing in structured menu and product data management for food delivery and commerce platforms. The company aggregates and normalizes large volumes of merchant and product catalog data on behalf of restaurant and retail clients. Woflow operates as a B2B SaaS/data services provider serving major food-tech and logistics ecosystems.
- Industry
- Menu & Product Data Management (Food Tech SaaS)
Attack summary
Severity: critical — The group claims hundreds of millions of records including PII and transaction/order data at scale; this volume of regulated personal and financial data from a data-aggregation platform serving major commerce ecosystems constitutes a critical-severity disclosure.ShinyHunters claims to have exfiltrated several hundreds of millions of records containing PII, transaction/order data, and other internal corporate data, and has issued a final warning deadline of 5 March 2026 before publishing the data alongside unspecified additional 'digital problems.'
Data the group says was taken
AI dossier — extracted from the leak post- Personally identifiable information (PII)
- Transaction/order data
- Internal corporate data
What the group claims
Several hundreds of millions of records containing PII, transaction/order data, other internal corporate data, and a lot more (you don't want us to say publicly) have been compromised. This is a final warning to reach out by 05 Mar 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 03 Mar 2026 | Warning: FINAL WARNING
Source
Indexed 3 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

