Ransomware victim disclosure
← All victimsLuna Group
Claimed by lamashtu · listed 17 days ago
Status timeline
- Listed
May 4, 2026
- Data leaked
At a glance
About the victim
AI dossier — public-source company profileLuna Group is an Egyptian conglomerate founded in 1966, operating across Egypt and parts of the Middle East and North Africa. The group imports, exports, and distributes raw materials, packaging materials, and machinery for pharmaceutical, food, cosmetics, fragrances, soap, and detergent industries. It comprises multiple subsidiaries including manufacturing and free-zone entities in Cairo, 6 October City, Alexandria, and Zarqa, Jordan.
- Industry
- Pharmaceuticals, Cosmetics & Industrial Raw Materials Distribution
- Address
- 72, EL Sharikat st., Ghamra, Cairo, Egypt (P.O.Box 43, Ghamra, Postal Code 11251)
- Founded
- 1966
Attack summary
Severity: high — Data has been published (disclosed status: data_published), confirming exfiltration of significant business data from a multi-subsidiary conglomerate operating across multiple countries, with likely exposure of commercial, financial, and operational records.The ransomware group Lamashtu claims to have compromised Luna Group, with the disclosure status listed as data_published, indicating exfiltration and publication of company data. No specific ransom demand or data size was stated in the post.
Data the group says was taken
AI dossier — extracted from the leak post- Corporate business records
- Financial documents
- Trade and distribution records
- Subsidiary company data
- Management and personnel information
- Customer and supplier data
What the group claims
Luna Group is a major Egyptian conglomerate established in 1966. It operates across the Middle East and North Africa (MENA) region, primarily focusing on pharmaceuticals, cosmetics, perfumes, and industrial raw materials.
Sources
Source
Indexed 17 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
