Ransomware victim disclosure
← All victimsRoyal Selangor
Claimed by BYOD · listed 23 hours ago
Status timeline
- ListedOct 5, 2026
- Data leakeddate unknown
At a glance
- Group
- BYOD
- Status
- Data leaked
- Country
- Malaysia
- Sector
- Manufacturing
- Listed on leak site
- Oct 5, 2026
About the victim
AI dossier — public-source company profileRoyal Selangor is a Malaysian pewter manufacturer and luxury goods company operating from Malaysia. The company maintains an e-commerce presence serving registered customers.
- Industry
- Luxury Goods & Jewelry
Attack summary
Severity: critical — Confirmed exfiltration of 300,000 customer records containing PII at scale (names, addresses, phone numbers, emails) plus financial data (purchase amounts, payment methods). Data published and monetization threat evident.The BYOD group claims to have exfiltrated both registered user and customer lists totaling 300,000 records, including names, emails, phone numbers, addresses, purchase amounts, and payment methods. The group states data has been published and threatens further action pending ransom negotiation.
Data the group says was taken
AI dossier — extracted from the leak post- Customer names
- Email addresses
- Phone numbers
- Physical addresses
- Purchase history/amounts
- Payment method details
What the group claims
Both, your Registered Users & Customer list have been affected. 300K Lines Total, Includes: Names, Emails, Phone Numbers, Addresses, Purchase Amount, Payment Method, Pretty Juicy stuff you don't want getting out there. Anyways, you know where to find us (contact tab). We will take you down when communication has been established between our team and yours.
Sources
- Victim siteroyalselangor.com
Source
Indexed 23 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

