Skip to main content

Ransomware victim disclosure

All victims

Bakery and Confectionery Grossarl

Claimed by MYDATA / ALPHA LOCKER · listed 3 days ago

117 GB
Data size
3d
Age
since listed · data leaked

Status timeline

  1. ListedJun 10, 2026
  2. Data leakeddate unknown

At a glance

Status
Data leaked
Country
Austria
Listed on leak site
Jun 10, 2026
Data size
117 GB

About the victim

AI dossier — public-source company profile

Bakery and Confectionery Grossarl is a small bakery and confectionery business located in Grossarl, Austria. The company operates a local food production facility serving the regional market.

Industry
Food & Beverage - Bakery and Confectionery
Address
Marktstr. 109, 5611 Grossarl, Austria

Attack summary

Severity: medium — Confirmed exfiltration of substantial data volume (117 GB) with public disclosure, but limited details on data sensitivity. Small bakery business suggests moderate scale of PII exposure rather than critical regulated data.

MYDATA/ALPHA LOCKER claims to have exfiltrated 117 GB of data from the company. The group has published the data on their leak site without specifying the exact nature of the stolen information.

medium

Data the group says was taken

AI dossier — extracted from the leak post
  • business records
  • operational data
  • potentially customer information

What the group claims

Bakery and confectionery located at 5611 Grossarl, Marktstr. 109, Austria.

The leak post

captured from the group's site
The data has been published
PYRAMIS METALLOURGIA S.A.PYRAMIS is the only producer of household electrical appliances in Greece, and at the same time, a Global Champion with presence in more than 85 countries and exports exceeding 97% of its production. PASSWORD for files - @m@0810#! 
The data has been published
Bangkok Eagle Wings Co.,Ltd.67/14 Mu 5 Chuamsamphan Rd. Kokfad. Nongchok. Bangkok 10530. Thailand.Stamping processWelding and assembly processMachining processPainting process 
The data has been published
With over 70 years of rich experience serving in the auto industry, they are one of India's largest car dealerships. 
The data has been published
117 GB data has stolenBakery and confectionery5611 Grossarl | Marktstr. 109+43 (0) 6414 / 2760 
The data has been published
At Verdugo Hills Dental in Glendale, CA, our experienced team is committed to more than just dentistry—we’re here to ensure your comfort and overall well-being every step of the way. From routine check-ups to advanced restorative treatments, we deliver comprehensive care with a gentle touch, alw... 
The data has been published
It is dental practice devoted to restoring and enhancing the natural beauty of your…

Screenshot of the leak post

Leak screenshot for Bakery and Confectionery Grossarl

Sources

Source

Indexed 3 days ago

This page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.

Is this your supplier? Your competitor? You?

Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

Disclosure context

About MYDATA / ALPHA LOCKER

MYDATA / ALPHA LOCKER is an emerging ransomware group first observed in May 2026 with financial extortion as its primary motivation, currently representing a nascent threat actor with a very limited publicly documented operational history. Given the extremely limited public reporting available from authoritative sources such as CISA, the FBI, Mandiant, or established security research organizations, the group's origin, affiliation, and infrastructure details remain largely unattributed and unconfirmed at this time. Based on available victim telemetry, the group has targeted at least one organization in Greece with a focus on the manufacturing sector, suggesting either opportunistic targeting or early-stage sector-specific reconnaissance, though no definitive attack methodology, initial access vectors, or encryption tooling details have been publicly documented to a verifiable standard. No notable high-profile campaigns, record ransom demands, or law enforcement actions have been publicly attributed to MYDATA / ALPHA LOCKER as of the time of this assessment. The group appears to be in its earliest operational phase, and its current status, including whether it operates as a Ransomware-as-a-Service model or as an independent closed group, cannot be confirmed without additional corroborating intelligence from authoritative sources; continued monitoring is warranted given its recent emergence. The group has been linked to 16 public disclosures across our corpus. First observed on a leak site on May 14, 2026; most recent post June 10, 2026. The operation is currently active.

Timeline of this disclosure

  • June 10, 2026Bakery and Confectionery Grossarl listed by MYDATA / ALPHA LOCKERon the group's public leak site
Data size
117 GB

Sector and geography

This disclosure adds to ransomware activity in the Food & Beverage sector. Geographically, Bakery and Confectionery Grossarl is reported in Austria, a country with 24 ransomware disclosures in our corpus.

If your organisation is affected

A listing by MYDATA / ALPHA LOCKER means Bakery and Confectionery Grossarl appeared on a ransomware extortion site and data attributed to it has been published. If this is your organisation, or a supplier you depend on, the priority is to confirm the intrusion and contain it before the window to act closes.

  • Engage your incident-response team and preserve forensic evidence before remediating — do not wipe affected systems first.
  • Force a password reset and revoke active sessions for exposed accounts; rotate any credentials, API keys or certificates that may have been in the stolen data.
  • Assess regulatory notification duties (GDPR, NIS2, sector regulators) — many carry a 72-hour reporting clock from awareness.
  • Monitor for the data appearing on MYDATA / ALPHA LOCKER's leak site and across paste and breach channels, and brief downstream partners who may be exposed through you.

How we know this. Darkfield monitors public ransomware leak sites continuously, archiving every new disclosure and the data later released against the victim. Each entry on this page is sourced from the operator's own publication and cross-checked against complementary OSINT feeds (RansomLook, ransomware.live, RansomWatch). We do not collect or host stolen data — only the metadata, timestamps and screenshots needed to make the public disclosure searchable and accountable. Records here are corrected when the original post is edited, retracted, or merged with another disclosure.