Ransomware victim disclosure
← All victimsLiztex Guatemala
Claimed by thegentlemen · listed 6 hours ago
Status timeline
- Listed
Jun 4, 2026
- Data leaked
At a glance
- Group
- thegentlemen
- Status
- Data leaked
- Country
- GT
- Sector
- Manufacturing
- Listed on leak site
- Jun 4, 2026
About the victim
AI dossier — public-source company profileLiztex Guatemala is a leading Guatemalan textile manufacturer with over 50 years of experience in producing fabrics. The company operates in the textile and fabric production sector.
- Industry
- Textile Manufacturing
- Employees
- 50+
Attack summary
Severity: critical — Confirmed exfiltration of 398 GB including regulated/sensitive data: medical records, financial data, employee personal data, and extensive business operations data. Both encryption and data theft confirmed with published proof.The threat actor claims to have breached and encrypted Liztex's network, exfiltrating approximately 398 GB of data. The group has published data as proof of the attack.
Data the group says was taken
AI dossier — extracted from the leak post- SAP system data
- Employee records and data
- Medical data
- Financial records
- Customer data
- Partner information
- Contracts and agreements
- Correspondence
- Production data
- Quality control records
- Logistics and planning documents
- Project files
- Business proposals and offers
- Subsidiary records
What the group claims
***.com Liztex is a leading Guatemalan textile manufacturer with over 50 years of experience in producing fabrics. We want to inform you that our group managed to breach and encrypt Liztex network. 398GB leaked from there as a result of this breach. What kind of data leaked: - SAP data - contacts - contracts - planning - logistics - projects data - personal data - employee data - medical data - partners data - customers data - financial data - correspondence - production data - quality control data - offers and proposals - subsidiary data - other sensitive business data
Sources
- Victim siteliztex.com
Source
Indexed 6 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.
