Ransomware victim disclosure
← All victimsGlobal Terminal Hizmetleri A.Ş.
listed as GTS (Global Terminal Hizmetleri A.Ş.) · Claimed by Deadlock · listed 6 days ago
Status timeline
- ListedAug 12, 2026
Current state: Listed for ransom
At a glance
- Group
- Deadlock
- Status
- Listed for ransom
- Country
- Turkey
- Sector
- Energy/Storage
- Listed on leak site
- Aug 12, 2026
About the victim
AI dossier — public-source company profileGTS (Global Terminal Hizmetleri A.Ş.) is the largest independent storage terminal for liquid fuels and oil in the Mediterranean region. It operates as a critical logistics and energy infrastructure provider serving the oil and gas sector.
- Industry
- Energy Storage & Logistics
Attack summary
Severity: critical — Confirmed exfiltration of sensitive PII at scale (107 passports, 1,712 bank statements, 231 credentials) combined with financial documents and infrastructure targeting. Critical infrastructure in energy sector with cross-border data exposure (Turkish company, Philippines/USD accounts referenced).Deadlock claims to have exfiltrated 27 GB of data (14,836 files) from GTS following a 72-hour ransom negotiation window. The leaked data includes personal identity documents, financial records, and corporate promissory notes linked to associated entities.
Data the group says was taken
AI dossier — extracted from the leak post- 107 passports (MRZ)
- 1,712 bank statements
- 212 promissory notes
- 231 BIR/eFPS credentials
The group's post references roughly 3 proof files.
What the group claims
GTS legally registered as Global Terminal Hizmetleri A.Ş. It is the largest independent storage terminal for liquid fuels and oil in the entire Mediterranean region.
The leak post
captured from the group's sitePublishes after: <b>18d 22h 40m</b> GTS legally registered as Global Terminal Hizmetleri A.Ş. It is the largest independent storage terminal for liquid fuels and oil in the entire Mediterranean region. LT Group / Fortune Tobacco Corp Amount: 27 GB | Files: 14,836 They ignored our messages for 72 hours.. Now we publish the details of the breach. Data leaked: 107 Passports (MRZ) 1,712 Bank Statements (PNB + Holco USD accounts) 212 Promissory Notes (Eton Properties, PHP 2.53B debt) 231 BIR/eFPS credentials Samples: Passport_Johnny_Tan.pdf Holco_USD_Statement.pdf Eton_Debt_212.pdf Full leak: August 18. Contact: Session ID provided in emails. Pay for the data or pay for its permanent deletion. Otherwise, the full dump will be public. Publishes after: <b>10d 12h 51m</b> United Fiber Optic Communication Inc. (UFOC) is an established, publicly traded telecommunications company from Taiwan. The company acts as a total solution provider for communication networks and specializes in the manufacture of fiber optic cables and the provision of integrated technological systems. Ahenk Laboratuvarı is an ISO 15189-accredited medical laboratory in Turkey, founded in 1998 and located in Istanbul-Ş…
Screenshot of the leak post

Sources
Source
Indexed 6 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

