Ransomware victim disclosure
← All victimsClipper Petroleum
Claimed by Akira · listed 5 months ago
Status timeline
- ListedJan 21, 2026
- Data leakeddate unknown
At a glance
- Group
- Akira
- Status
- Data leaked
- Country
- United States
- Sector
- Energy
- Listed on leak site
- Jan 21, 2026
- Data size
- 60 GB
About the victim
AI dossier — public-source company profileClipper Petroleum is a petroleum marketer based in Flowery Branch, Georgia, with over 90 years of operating history. The company functions as a wholesale fuel distributor and also operates convenience stores and fast food retail locations. It serves both commercial and consumer markets in the southeastern United States.
- Industry
- Petroleum Marketing & Fuel Distribution
- Address
- Flowery Branch, Georgia, United States
Attack summary
Severity: critical — The threat actor claims exfiltration of credit card details and PII for both customers and employees at scale (60 GB), alongside financial records — constituting regulated sensitive data (payment card data, personal identifiable information) with disclosed status of data_published.Akira claims to have exfiltrated over 60 GB of corporate data from Clipper Petroleum, including customer and employee personal documents, financial and accounting records, contracts, credit card details, and NDAs, with publication of the data described as imminent.
Data the group says was taken
AI dossier — extracted from the leak post- Customer personal documents
- Employee personal documents
- Internal confidential files
- Financial and accounting information
- Contracts and agreements
- Credit card details
- Non-disclosure agreements (NDAs)
What the group claims
Clipper Petroleum is a petroleum marketer based in Flowery Branch , Georgia, with over 90 years of experience. The company operates as a convenience store and fast food retailer while also serving as a wholesale fuel distributor. We will upload over 60gb of corporate data soon. Customer and emp loyee personal documents, internal confidential files, detailed f inancial and accounting information, contracts and agreements, cr edit card details, NDAs and so on.
Source
Indexed 5 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

