Ransomware victim disclosure
← All victimsFanasa
Claimed by Stormous · listed 2 months ago
Status timeline
- Listed
Mar 29, 2026
- Data leaked
At a glance
- Group
- Stormous
- Status
- Data leaked
- Country
- Mexico
- Sector
- Technology
- Listed on leak site
- Mar 29, 2026
About the victim
AI dossier — public-source company profileFanasa (fanasa.com) is a Mexican company operating in the trade or distribution sector, based in Mexico. Beyond the domain and country of origin, limited public information is available from the leak post or public site to further characterize its scale or specific operations.
- Industry
- Wholesale Distribution / Trade (Mexico)
Attack summary
Severity: critical — Confirmed exfiltration of regulated PII at scale including taxpayer IDs (RFC), financial records, CFDI fiscal documents, and internal corporate data in Mexico — constituting regulated sensitive data under Mexican data protection law (LFPDPPP). Full system access claimed with data actively offered for sale.Stormous claims to have exfiltrated approximately half of Fanasa's data, including PII, electronic fiscal documents (CFDI/XML), financial transaction records, commercial invoices, taxpayer identification numbers (RFC), client and vendor databases, internal corporate documentation, administrative/system files, engineering drawings, and email/application data. The group states all extracted data is offered for sale and claims full access to the company's systems was obtained.
Data the group says was taken
AI dossier — extracted from the leak post- Personally Identifiable Information (PII)
- Electronic Fiscal Documents (CFDI/XML)
- Financial Transaction Records
- Commercial Invoices & Billing Data
- Taxpayer Identification Numbers (RFC)
- Client & Vendor Database
- Internal Corporate Documentation
- Administrative/System Files
- Engineering Drawings & Schematics
- Project Planning & Execution Documents
- Email/Communication Data
- Application/Database Data (AYEAPLICACIONES, BDATOSFITCLOD)
- Software/Installation Files (AUTOBOU)
- Personal/Miscellaneous Files
What the group claims
Personally Identifiable Information (PII), Electronic Fiscal Documents (CFDI/XML), Financial Transaction Records, Commercial Invoices & Billing Data, Taxpayer Identification Numbers (RFC), Client & Vendor Database, Internal Corporate Documentation, Administrative/System Files, operational records, engineering drawings, schematics, Project Planning & Execution Documents, Email/Communication/System/Application Data, database, Log Data, Software/Installation/Program Files
The leak post
captured from the group's siteInitial Access Brokers - Long-Term Collaboration We are currently seeking reliable Initial Access Brokers for long-term collaboration. ** Please do not waste time attempting complex exploit development or direct EDR confrontation. We are interested exclusively in stable corporate access. Local user access is acceptable. * Small to mid-sized enterprises: fixed payment starting at * Large enterprises: revenue share from final settlement FANASA.COM Half the data has been extracted Personally Identifiable Information (PII), Electronic Fiscal Documents (CFDI/XML), Financial Transaction Records, Commercial Invoices & Billing Data, Taxpayer Identification Numbers (RFC), Client & Vendor Database/Internal Corporate Documentation Administrative/System Files/ADMIN, DOAS, operational records, engineering drawings, schematics... Project Planning & Execution Documents... (Folders/Files) Email/Communication/System/Application Data AYEAPLICACIONES database/Log Data BDATOSFITCLOD, Software/Installation/Program Files AUTOBOU, Personal/Miscellaneous Files AvenaCubana All of this data is offered for sale (user information: email, phone number, full name, date of birth / payment and bookin…
Data the group says was taken
- PII
- financial
- emails
- contracts
Sources
- Victim sitefanasa.com
- Leak posthttp://pdcizqzjitsgfcgqeyhuee5u6uki6zy5slzioinlhx6xjnsw25irdgqd.onion
Source
Indexed 2 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
