Ransomware victim disclosure
← All victimsCentral Romana Corporation
listed as centralromana.com.do · Claimed by Lockbit5 · listed 2 days ago
Status timeline
- ListedJun 11, 2026
- Data leakeddate unknown
At a glance
- Group
- Lockbit5
- Status
- Data leaked
- Country
- Dominican Republic
- Listed on leak site
- Jun 11, 2026
About the victim
AI dossier — public-source company profileCentral Romana Corporation is a Dominican Republic-based conglomerate founded in 1912, originally established as a sugar producer and now the country's largest in that sector. The company has diversified across chemicals, free-trade zones, livestock, meat and dairy processing, construction materials, iron production, port and airport operations, real estate, and tourism (including the Casa de Campo resort).
- Industry
- Agro-industrial & Tourism Conglomerate
- Address
- Dominican Republic (La Romana region implied)
- Founded
- 1912
Attack summary
Severity: medium — Data has been published by the group and the victim is a large, critical infrastructure operator (ports, airports, agro-industrial processing) in a strategically important Caribbean jurisdiction. However, without details on data type, scale, or proof quantity, and given the lack of stated ransom or operational disruption claims, severity is moderate rather than high.LockBit5 claims to have attacked Central Romana Corporation. The leak post provides minimal detail on the specific nature of the breach (encryption, exfiltration, or both) or the data types compromised.
What the group claims
Established in 1912, Central Romana Corporation is the leading agro-industrial and tourism company i...
Sources
Source
Indexed 2 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

