Vietnam's Mat Bao and Thai Lion Air land on leak sites

Published

The ransomware crew Rhysida says it has stolen 106.8 GB of data, 746,108 files, from Mat Bao Corporation, a Vietnamese company that sells domain names, cloud hosting, business email and cloud server storage. What it is advertising goes well beyond customer records. According to the listing, recorded on 2 October by the independent tracker ransomware.live on its victim page for the claim, the alleged haul includes correspondence with three of Vietnam's internet and cryptography regulators.

The Mat Bao listing was one of eight leak-site claims against Southeast Asian organisations in our incident tracking for the week beginning 28 September. That is ordinary for the region, which has run at 5 to 17 a week since July. The names are not: an airline, a large coal producer, a children's hospital and a company that hosts other businesses' websites and email.

Regulator files, not just spreadsheets

Rhysida's post sorts the alleged data into five groups. One is government inspection material, including an inspection decision dated 29 April 2025 from NEAC, Vietnam's National Electronic Authentication Centre, issued against what the post calls "the certification authority", along with working minutes that name state inspectors and company staff. Another is correspondence with VNNIC, the body that runs the .vn domain space, with NEAC, and with the Government Cipher Committee, the state cryptography authority. The post says that correspondence covers "RSA-1024 token vulnerabilities" but gives no further detail.

The rest is typical extortion material, listed in unusual detail: business registration papers bearing the owner's signature, shareholder records and tax filings dated January 2026, scans of employee national ID cards and passports, staff lists, and documents from a commercial dispute and internal investigations. Rhysida is profiled on our actor page.

An airline, a coal miner and a children's hospital

The same day, 2 October, Qilin added Thai Lion Air to its site without describing any data. The tracker page carries Hudson Rock infostealer figures counting 75 compromised employees and 6,685 compromised users linked to the airline's domain. That describes exposure built up over time, not how any intrusion began.

RansomHouse listed PT Indo Tambangraya Megah, which the tracker's profile describes as a leading coal producer, on 2 October, giving an attack date of 12 September.

In the Philippines, SafePay named fedelmundo.com.ph, an institution whose profile traces its origins to the Children's Memorial Hospital founded in 1957 by the pediatrician Dr. Fe del Mundo, while Qilin listed the diagnostics provider New World Diagnostics. The Gentlemen added Vietnam's VUS English centre chain and the Indonesian restaurant chain Solaria, and NetRunner listed Malaysia's Main Place Mall.

Claims, not confirmed breaches

Every listing here was written by the gangs themselves, a pattern we also traced in our September look at listed companies on Southeast Asia's leak sites. We found no public statement from Mat Bao, Thai Lion Air or the other organisations named confirming an incident at the time of writing, and crews do exaggerate and recycle old data. The leak sites sit on .onion addresses, which we do not link. A ninth listing filed under Timor-Leste the same week belongs to a French company and is excluded from the count above.

Mat Bao customers should lock down accounts now

Mat Bao customers need not wait for confirmation: change hosting control panel, email and registrar passwords, turn on two-factor authentication and domain transfer locks, and watch DNS records for unexplained changes. Staff whose identity documents may be in the dump should expect targeted phishing that quotes real personal details. Vietnam's personal data protection rules oblige organisations that confirm a breach of personal data to notify the Ministry of Public Security. See our Vietnam country page.

Eight claims in a week is nothing new for the region. A hosting provider's regulator correspondence on offer is, because whoever buys or downloads it could learn how a piece of Vietnam's internet plumbing is supervised, and that knowledge outlasts any ransom deadline.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions