Ransomware victim disclosure
← All victimsUnknown
Claimed by Sovcali · listed 2 hours ago
Status timeline
- ListedAug 21, 2026
Current state: Negotiating
At a glance
- Group
- Sovcali
- Status
- Negotiating
- Listed on leak site
- Aug 21, 2026
- Data size
- 35 GB
About the victim
AI dossier — public-source company profileUnknown company. No identifying information provided in the leak post or accessible public site.
Attack summary
Severity: medium — Data exfiltration of significant volume (35 GB) claimed, but no proof files published yet, no data types specified, and victim identity unknown. Severity is constrained by lack of specificity about what data exists and whether it contains regulated or sensitive material.Sovcali claims to have exfiltrated 35 GB of company data and threatens to release an additional 35 GB within two days if negotiations do not proceed.
What the group claims
Ransomware group claims to possess company data and threatens to release an additional 35 gigabytes within two days if negotiations do not proceed. Group states they have refrained from contacting competitors and are seeking direct negotiation with the company.
The leak post
captured from the group's siteFri, Aug 21 · 02:43 AM In accordance with our serious intent and our exclusive interest in negotiating solely with the company itself, we have refrained from initiating any discussions with any other company or competitor. To demonstrate that we are in possession of the data in question, we will release an additional 35 gigabytes of material belonging to this company within the next two days.We trust that the company’s officials will reach a definitive decision at the earliest opportunity
Screenshot of the leak post

Sources
Source
Indexed 2 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

