Ransomware victim disclosure
← All victimsNeo Group
Claimed by Qilin · listed 5 months ago
Status timeline
- ListedJan 15, 2026
- Data leakeddate unknown
At a glance
About the victim
AI dossier — public-source company profileNeo Group Ltd is Singapore's leading provider of food and catering solutions, operating a portfolio of over 30 established and emerging brands including Neo Garden, Orange Clove, and PrimaDéli. The company operates across multiple segments including catering, manufacturing, retail, supplies and trading, beverages, and property. Its trading network spans over 30 countries worldwide, and it has held the No. 1 Events Caterer position in Singapore since 2011.
- Industry
- Food & Catering Services
- Address
- 30B Quality Rd, Singapore 618826
- Founded
- 1992
Attack summary
Severity: high — Data has been published by the ransomware group, confirming exfiltration. Neo Group is a publicly listed company operating across 30+ countries with consumer-facing brands; published data likely includes business-sensitive and potentially personal/employee data regulated under Singapore's PDPA. Confirmed data publication elevates severity to high.Qilin claims to have attacked Neo Group and has published data (disclosed status: data_published), indicating exfiltration of company data. No specific ransom amount or data volume was stated in the leak post.
Data the group says was taken
AI dossier — extracted from the leak post- Corporate business data
- Operational records
- Potentially personal data (PDPA-regulated)
What the group claims
N/A
The leak post
captured from the group's siteLaw Firms & Legal Services [John G Yphantides A Professional Law](http://ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion/site/blog?uuid=1e464ce5-6e74-4e62-be0b-eac503e43af8) Law Firms & Legal Services Law Firms & Legal Services [Keller Williams Real Estate - Exton](http://ijzn3sicrcy7guixkzjkib4ukbiilwc3xhnmby4mcbccnsd7j2rekvqd.onion/site/blog?uuid=ac8e3226-6965-4f8e-a2d5-53a0dbce8535)
Sources
Source
Indexed 5 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

