Ransomware victim disclosure
← All victimsLava International Limited
listed as LAVA · Claimed by Snatch · listed 5 years ago
Status timeline
- ListedDec 26, 2021
- Data leakeddate unknown
At a glance
- Group
- Snatch
- Status
- Data leaked
- Country
- India
- Sector
- Manufacturing
- Listed on leak site
- Dec 26, 2021
About the victim
AI dossier — public-source company profileLava International Limited is a leading mobile handset company headquartered in India that designs and manufactures mobile phones. The company has expanded its operations to multiple countries across the world. Since its inception, Lava has focused on building a strong ecosystem for mobile handset design and manufacturing.
- Industry
- Mobile Handset Design & Manufacturing
Attack summary
Severity: high — Data has been confirmed as published ('data_published' status) by the Snatch group against a large multinational mobile handset manufacturer, indicating confirmed exfiltration of significant business data; the scale of operations across multiple countries suggests material corporate data is at risk.The Snatch ransomware group claims to have attacked Lava International Limited and has published data as part of a disclosed leak, though the specific nature of the attack (encryption, exfiltration, or both) and the volume of data are not explicitly stated in the truncated post.
What the group claims
Lava International Limited is a leading Mobile Handset Company in India and has expanded its operations to multiple countries across the world. Right from its inception Lava has been at the forefront of building a strong ecosystem of design and manufacturing of mobile handsets. The
Source
Indexed 5 years agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

