Leak sites turn on Southeast Asia's listed companies

Ransomware crews posted about as many Southeast Asian victims to their leak sites this week as they have all summer. What changed is the size of the names. In the seven days to September 2, IntelFusions' incident tracker recorded 14 fresh claims against organizations in the region, in line with the 11 to 14 a week it has logged since early August. Four of those claims name companies listed on a stock exchange, and another names one of Vietnam's largest consumer lenders.

All of these are extortion claims made by the gangs themselves. None has been verified by IntelFusions, and a leak-site listing is not proof that data was taken.

Thailand's largest fuel retailer on a wolf's list

The biggest name is PTT Oil and Retail Business, the fuel and convenience-store arm of Thailand's state-controlled PTT group, listed on the Stock Exchange of Thailand and the country's largest fuel retailer. Dire Wolf listed it on September 2. The same crew had listed PT Intraco Penta Tbk, an Indonesia-listed heavy-equipment group, a day earlier.

Dire Wolf is worth watching in its own right. First documented in May 2025, it runs a Go-based locker and is assessed to be a tight core team rather than a broad affiliate program. It was quiet in IntelFusions' data for most of the summer, then posted 43 victims in August alone, and now stands at 52 since June.

The Gentlemen, currently one of the two most prolific crews on the leak sites, added two more listed manufacturers: Thai Film Industries PCL, a SET-listed maker of BOPP packaging film, on August 30, and EP Manufacturing Bhd, a Bursa Malaysia-listed automotive manufacturer, on August 31. INC Ransom listed the domain cimbsecurities.com in Malaysia on the same day; the domain carries the CIMB Securities brand, and IntelFusions has not established which entity operates it today. And Black X, a crew that only surfaced in June, listed FE Credit, a major Vietnamese consumer-finance company, on August 30.

Why listed victims are a different problem

A leak-site post against a small private firm is a private crisis. A post against a listed company puts the claim in front of investors, regulators and the exchange, whether or not it is true, and pressures the board to say something before it knows what happened. That is the leverage the crews are after.

The region's regulators are tightening. Indonesia's data-protection authority is now issuing fines of up to 2% of annual revenue under the PDP law, Thailand's National Cyber Security Agency has mandatory assessment guidelines for critical-infrastructure operators, and Malaysia lists financial-sector security among its national priorities. Any confirmed breach among this week's names lands inside those regimes.

The rest of the week's list

The remaining claims fit the pattern IntelFusions described in August, when hotels rather than hospitals dominated the regional feed: Eclipse listed Royal Plaza on Scotts, a five-star hotel on Singapore's Orchard Road; Qilin listed Malaysia's CareClinics, a Philippine port operator and a Singapore technology firm; and Krybit, MedusaLocker and Global each added a Thai or Singaporean victim. Nothing in the week suggests a coordinated campaign against the region. Ten different crews are involved, and none of them has said anything about Southeast Asia in particular.

Treat the claim as an alarm, not a verdict

For the companies named, the work is the same whether or not the claim is true: confirm or rule out an intrusion, preserve logs, prepare a disclosure. For their peers, the useful signal is the crews. Dire Wolf's documented focus is manufacturing and technology, three of the week's listed victims are manufacturers, and The Gentlemen's affiliates have been documented encrypting within two days of a break-in. Volume on the leak sites is not news. A change in who is being named is.

This briefing is provided by IntelFusions for informational and defensive purposes only. It summarizes extortion claims published by ransomware leak sites. Those claims are made by the attackers, are unverified, and may be false, exaggerated, or recycled from earlier breaches. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions