Sponsored by Hudson Rock – Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are impacting your business
Group: Thegentlemen
Discovered by ransomware.live: 2025-12-12
Estimated attack date: 2025-12-12
Description:
The entire infrastructure of a major regional retail grocery network—comprising approximately 80 grocery stores, about 40 liquor outlets, and roughly 50 pharmacies, along with its franchise operations—has been compromised, with all data stolen and encrypted. The targeted company reports an annual revenue of $1.4 to $1.8 billion (according to various 2025 estimates). The exfiltrated data includes all insurance payouts (even detailed records of payouts to families of deceased employees, listing cause of death and amounts paid), complete personnel records for all employees and executives (containing SSN, date of birth, full name, address, passport details, and W-9 forms), every financial document, records of active deals and income/expenses, as well as all documentation and insurance records for the company's movable and immovable property. http://i2ohjeeqe37jre4f2u7pyq73cbm6lecumdxapkvrlryna6rc3it4zsid.onion (your key in Tox Chat)
Leak Screenshot:
Legal Disclaimer: Ransomware.live does not engage in the acquisition, exfiltration, downloading, possession, hosting, access, consultation, redistribution, or disclosure of unlawfully obtained data. This platform indexes only publicly visible information posted by ransomware operators and open web sources without accessing or obtaining the underlying stolen content. The service is provided to support public awareness, legitimate research, and cyber-resilience. No stolen personal or confidential data is collected or distributed via this site.