DisclosureLens
GLOBALMalwareEnergy & UtilitiesUtilitiesRansomwareJRansom DemandedActor NamedMedium

Petro-Diamond

bd_3d1241b838ba9fe2 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Filed

Sep 29, 2025

To disclose

Affected

Not disclosed

Confidence

50%
Full breach record for Petro-Diamond

Threat-actor claim — not a regulatory filing

This row is a claim by the ransomware group J on its public extortion blog. It has not been validated by the victim or any regulator. Treat attribution and counts as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.

Group activity: EnergyDiscovered: 2025-09-29

Source: Ransomware.live

Post text · scraped from the leak site

Petro-Diamond is a commodity trading subsidiary of Mitsubishi Corporation. It's involved in the trade and marketing of petroleum and its derivatives, liquefied petroleum gas (LPG), and carbon-related materials. Also, they handle petrochemicals and participate in energy project developments.

Incident timeline — mostly unverified

? — ?

Breach window unknown

Sep 29, 2025

Claim posted

No filing yet · watching

Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.

Claim → filing

Compliance clock

Not assessable

Tracked as a single-filing incident — the only disclosure on record for this event so far.Unverified claimView incident

Evidence ladder

Leak-site claimThis record

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filing

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.

No regulatory filing corroborates this yet — it is the attacker's own assertion. Watch this entity to be notified the moment a filing corroborates or contradicts it.

Source ceiling

  • actor name
  • victim claim
  • ransom/leak status
  • discovery date
  • materiality
  • notification
  • affected count
  • confirmed data types
  • compliance clock

The ✕ fields stay blank until a regulatory filing or victim disclosure lands.

About this groupFirst seen 2025-02-17

j

According to ransomware.live, J is an emerging ransomware group that launched its leak site in May 2025, claiming over 41 victims by late 2025 including FAI Aviation Group (Germany), operating primarily as a leak-site-centric extortion identity with limited public technical analysis.

41 victims claimed globally41 tracked hereFull profile →