Ransomware victim disclosure
← All victimsTharisa
Claimed by UmBra · listed 5 hours ago
Status timeline
- ListedOct 7, 2026
- Data leakeddate unknown
At a glance
- Group
- UmBra
- Status
- Data leaked
- Country
- South Africa
- Sector
- Manufacturing
- Listed on leak site
- Oct 7, 2026
About the victim
AI dossier — public-source company profileTharisa is a Cyprus-based mining group specializing in the production and processing of platinum group metals (PGMs) and chrome. The company operates major facilities in South Africa with development projects in Zimbabwe.
- Industry
- Mining & Minerals Processing (Platinum Group Metals & Chrome)
Attack summary
Severity: medium — Data has been published (disclosed status: data_published), indicating confirmed exfiltration. However, the leak post provides no details on data scope, sensitivity, or proof files. Mining operations involving PGMs and chrome involve operational, supply-chain, and potentially employee data of moderate sensitivity.The UmBra group claims to have attacked Tharisa. The leak post does not specify whether data was exfiltrated, encrypted, or both, nor does it detail what data categories are at stake.
What the group claims
Tharisa is a Cyprus-based mining group focused on the production and processing of platinum group metals (PGMs) and chrome, with major operations in South Africa and development projects in Zimbabwe.
Sources
Source
Indexed 5 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

