Ransomware victim disclosure
← All victimsXiamen Tungsten Co. (XTC)
Claimed by beast · listed 2 months ago
Status timeline
- Listed
Mar 31, 2026
- Data leaked
At a glance
- Group
- beast
- Status
- Data leaked
- Country
- CN
- Sector
- Manufacturing
- Listed on leak site
- Mar 31, 2026
About the victim
AI dossier — public-source company profileXiamen Tungsten Co., Ltd. (XTC, SSE: 600549) is a Chinese state-linked publicly listed company headquartered in Xiamen, Fujian, with a market capitalisation of approximately USD 13.56 billion. The company is one of the world's largest producers of tungsten products, rare earth materials, and lithium battery materials, operating mines, processing facilities, and international trade subsidiaries. It maintains extensive R&D, ERP, HR, and supply chain infrastructure across domestic and overseas operations.
- Industry
- Tungsten & Rare Metal Mining, Processing & Advanced Materials Manufacturing
- Address
- Xiamen, Fujian Province, China
- Employees
- 10000+
- Founded
- 1997
Attack summary
Severity: critical — The actor claims exfiltration of a comprehensive dataset including full workforce PII and payroll at scale, SSO credentials enabling further network access, proprietary chemical formulas and alloy recipes constituting trade secrets, financial and board-level strategic data, supply chain intelligence, and politically sensitive Party Committee records — all from a USD 13.56 billion publicly listed strategic-sector company with national security implications. The breadth, volume (160 GB+), and sensThe threat actor 'Beast' claims to have achieved full infrastructure compromise of XTC, exfiltrating over 160 GB of SQL database backups covering ERP (Microsoft Dynamics AX), HR with full workforce PII and payroll, LIMS with chemical formulas and alloy recipes, financial reporting, SSO credentials, Party Committee records, board materials, and supply chain data; the dataset is offered for sale exclusively to a single buyer for 20 BTC.
Data the group says was taken
AI dossier — extracted from the leak post- Full workforce PII and payroll (HR database, 14.7 GB)
- ERP system data and business logic (Dynamics AX, domestic and international)
- Chemical formulas and alloy recipes (LIMS)
- Single Sign-On credentials and network access tokens
- Executive dashboards and strategic forecasts (Business Intelligence)
- Consolidated financial reporting and departmental budgets
- Board meeting materials and executive decisions
- Supply chain logistics contracts and shipping routes
- Production scheduling and manufacturing execution data
- Geological surveys and mine mapping data (38 GB)
- Quality control archives and product testing history
- Communist Party Committee political records
- ESG audits and supplier certifications
- Health, safety and environment compliance records
- Corporate WeChat Work communications integration data
- Legacy HR personnel archives
- Factory floor sensor acquisition logs
- Internal web API executable code (SpringBootBase.jar)
- Tungsten market price quotes and commercial bids
- Document approval workflows and e-signature logic
What the group claims
Xiamen Tungsten Co. (XTC) - Full Infrastructure Dump 2026 The market capitalization $13.56 billion USD (600549.SS Shanghai Stock Exchange) Size: 150GB+ (.bak files) with FULL ACCES Content: ERP (Dynamics AX), HR (14GB), LIMS (Lab Tech), Party Committees, ESG, SCM. Format: SQL Backups. FOR SALE IN 1 HANDS ! Price: 20btc This inventory represents a total infrastructure compromise of Xiamen Tungsten Co., Ltd. (XTC). The dataset includes over 160GB of SQL backups covering R&D, ERP, HR, and Government relations. I. High-Capacity Strategic Assets (Over 5GB) ecology202306091936.bak (38GB) � Geological surveys, mine mapping, and environmental resource monitoring. QL_DataCenter_backup (15.8GB) � Centralized corporate data warehouse aggregating all subsidiary streams. QcAdmin20240109.bak (15.5GB) � Master quality control archive; includes all technical specs and product testing history. MCHRDB20260322000000.BAK (14.7GB) � Main Corporate HR database; full PII and payroll of the entire workforce. 11MicrosoftDynamicsAX_model.bak (9.07GB) � Blueprint of the ERP system including business logic and financial structures. smartbi_backup (7.56GB) � Business Intelligence platform with executive dashboards and strategic forecasts. BB.bak (5.89GB) � "Big Business" database containing consolidated financial reporting. QL_SSO_backup (5.38GB) � Single Sign-On hub; contains user credentials and network access tokens. II. Core Operational & Manufacturing Databases (500MB � 5GB) Global_Erp.bak (3.66GB) � ERP system for international trade and overseas branches. QL_ERP.bak (3.68GB) � Domestic resource planning, procurement, and asset management. QL.LIMS.JL_backup (2.14GB) � Lab Information Management; contains chemical formulas and alloy recipes. QL_HSE_GE_backup (1.97GB) � Global Health, Safety, and Environment regulatory compliance records. QL.ESG_backup (1.80GB) � Environmental, Social, and Governance audits and supplier certifications. QL_Scheduler_backup (1.46GB) � Master production scheduling and factory capacity planning. BOStore_backup (1.31GB) � Business Object Store; history of sales orders and transactions. XTCWZ_20210207.bak (930MB) � Material and technical supply database (inventory and spare parts). SCM_DB_backup (906MB) � Supply Chain Management; logistics contracts and shipping routes. QL_MES_backup (721MB) � Manufacturing Execution System; real-time shop floor data. QL_GoView_backup (715MB) � Production visualization and real-time monitoring dashboards. qcadmin20231229.bak (606MB) � Quality control administration and defect analysis logs. GEQYWX_20240313.bak (562mb) � Integration database for WeChat Work corporate communications. III. Corporate, Political & Infrastructure Modules (Under 500MB) ql_party_yj_backup (334MB) � Records of the Communist Party Committee and political leadership. XTC_WorkFlowTest (330MB) � Digital document approval routes and e-signature logic. BFDB2_backup (306MB) � Business Finance database; departmental budgets and planning. QL_Board_backup (288MB) � Materials for Board meetings and executive decision-making. XTHRDB-20190402.BAK (264MB) � Legacy HR archive for historical personnel tracking. SSISDB_backup (222MB) � SQL Server Integration Services; logic for cross-system data transfers. QL_Maint_backup (218MB) � Equipment maintenance schedules and industrial repair logs. QL_DAQ_backup (182MB) � Data Acquisition system logs from factory floor sensors. VUEHRDB.BAK (156MB) � HR database specifically for IT and web-development teams. SpringBootBase.jar (81MB) � Executable code for the internal web API and microservices. TungstenQuote_backup (10MB) � Current commercial bids and tungsten market price quotes.
The leak post
captured from the group's siteAJU Pharm Co., Ltd. is a prominent South Korean total healthcare company founded in 1953. For over 70 years, it has evolved from a manufacturer of raw materials into a global pharmaceutical group specializing in prescription drugs, medical devices, and health supplements P U B L I S H E D
Sources
Source
Indexed 2 months agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
