Ransomware victim disclosure
← All victimsSFA Engineering
Claimed by Underground · listed 9 months ago
Status timeline
- Listed
Aug 15, 2025
- Data leaked
At a glance
- Group
- Underground
- Status
- Data leaked
- Country
- South Korea
- Sector
- Technology
- Listed on leak site
- Aug 15, 2025
- Data size
- 2.3 TB
- Ransom demanded
- $1.7B
- Estimated revenue
- $1.7B
About the victim
AI dossier — public-source company profileSFA Engineering is a South Korean engineering company. Limited publicly available information is available from the clearnet domain sfa.co.kr.
- Industry
- Engineering & Design
Attack summary
Severity: high — Confirmed data exfiltration of 2.3 TB with public disclosure; extremely high ransom demand ($1.7B) suggests significant data sensitivity or operational criticality, though specific data types are not detailed in the post.The Underground group claims to have exfiltrated 2.3 TB of data from SFA Engineering. The group is demanding $1.7B ransom and has published the data on their leak site.
Data the group says was taken
AI dossier — extracted from the leak post- company records
- business documents
- technical files
What the group claims
Revenue: $1.7 Billion Type: Industry Size: 2,3 TBytes
The leak post
captured from the group's siteAll data | Underground store Data Announcements All data Afghanistan Albania Algeria American Samoa Andorra Angola Anguilla Antigua and Barbuda Argentina Armenia Aruba Australia Austria Azerbaijan Bahamas Bahrain Bangladesh Barbados Belarus Belgium Belize Benin Bermuda Bhutan Bolivia Bonaire, Sint Eustatius and Saba Bosnia and Herzegovina Botswana Brazil British Virgin Islands Brunei Darussalam Bulgaria Burkina Faso Burundi Cambodia Cameroon Canada Cape Verde Cayman Islands Central African Republic Chad Chile China Colombia Comoros Congo Congo, Democratic Republic Cook Islands Costa Rica Côte d`Ivoire Croatia Cuba Curaçao Cyprus Czech Republic Denmark Djibouti Dominica Dominican Republic East Timor Ecuador Egypt El Salvador Equatorial Guinea Eritrea Estonia Ethiopia Falkland Islands Faroe Islands Fiji Finland France French Guiana French Polynesia Gabon Gambia Georgia Germany Ghana Gibraltar Greece Greenland Grenada Guadeloupe Guam Guatemala Guinea Guinea-Bissau Guyana Haiti Honduras Hong Kong Hungary Iceland India Indonesia Iran Iraq Ireland Isle of Man Israel Italy Jamaica Japan Jordan Kazakhstan Kenya Kiribati Kuwait Kyrgyzstan Laos Latvia Lebanon Lesotho Liberia Libya Liechtenst…
Sources
Source
Indexed 9 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
