Roshan Packages
bd_23ad16784ce59273 · schema v1 · pii pii-v1
Full breach record for Roshan Packages →Threat-actor claim — not a regulatory filing
This row is a claim by the ransomware group Sarcoma on its public extortion blog. It has not been validated by the victim or any regulator. Treat attribution and counts as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.
Source: Ransomware.live
Post text · scraped from the leak site
Roshan Packages In 1959, Dr. Aijaz Hassan Qureshi began a journey of excellence after returning from Germany with a PhD. He launched Urdu Digest which served as the onset of an extraordinary journey forward. Urdu Digest became Pakistan’s most circulated publication due to its engaging content pertinent to attentive and thoughtful editorials and subject matters. Roshan Enterprises launched in 1989 to export Pakistan’s fruits to the world and was a pioneer and forerunner in recognizing the potential in Pakistan’s fruit crops. At this time, fruit was omitted in Pakistan’s export culture, and Roshan Enterprises invited the prospect through intellectual marketing techniques and advanced fruit processing units. The enterprise exceeded expectations and evolved into Pakistan’s largest fruit exporter. The corporation’s futuristic approach and high volume export demand prompted the setup of an in-house packaging unit. In 2002, Roshan Packages Limited was established to meet internal demand for Corrugated Packaging. After this momentous initiation, the company grew exponentially and established European Flexible Packaging and Co-extruded Film Solution Plants in 2011 and 2015, respectively. Presently, Roshan Packages Limited specialises in world-class Co-extruded films, Flexible Packaging, and Corrugated Packaging materials and solutions, all in tune with current industry trends. Consequently, Roshan Packages Limited has gained an outstanding pool of national and international customers: a credit to its remarkable progression.Geo: Pakistan - Leak size: 382 GB Archive - Contains: Files
J jump to incidentP pin to compareR raw source
Incident timeline — mostly unverified
? — ?
Breach window unknown
Mar 26, 2025
Claim posted
—
No filing yet · watching
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Claim → filing
—
Compliance clock
Not assessable
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.
No regulatory filing corroborates this yet — it is the attacker's own assertion. Watch this entity to be notified the moment a filing corroborates or contradicts it.
Source ceiling
- actor name
- victim claim
- ransom/leak status
- discovery date
- materiality
- notification
- affected count
- confirmed data types
- compliance clock
The ✕ fields stay blank until a regulatory filing or victim disclosure lands.
sarcoma
According to ransomware.live, Sarcoma is a ransomware group that debuted in October 2024, immediately ranking among the top three most active groups globally and surpassing 116 documented victims by mid-2025, targeting mid-market companies across manufacturing, retail, healthcare, legal, and business services with roughly 50% of victims in the United States.