DisclosureLens
GLOBALMalwareFinancial ServicesFinanceRansomwareCyclopsRansom DemandedActor NamedMedium

ALTARGRUP

bd_69edb3de81ca809e · schema v1 · pii pii-v1

Severity

Medium

Discovered

Filed

Jun 29, 2023

To disclose

Affected

Not disclosed

Confidence

50%
Full breach record for ALTARGRUP

Threat-actor claim — not a regulatory filing

This row is a claim by the ransomware group Cyclops on its public extortion blog. It has not been validated by the victim or any regulator. Treat attribution and counts as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.

Group activity: Financial ServicesDiscovered: 2023-07-01

Source: Ransomware.live

Post text · scraped from the leak site

Within the roof of Altar Group, the foundations of which were laid in 2012; We operate in 6 different areas: mobile phone insurance, renewal center, domestic and foreign trade, agriculture animal husbandry, software and consultancy. As Altar Group, our corporate strategy is to expand the knowledge and experience we have gained in all areas in which we operate and to carry out studies that will benefit the environment and society. In this direction, with our team of versatile professionals, we continue to work to carry forward all the sectors we are in with a service understanding based on quality and trust in national and international dimensions.We carry out damage assessment and repair activities with the insurance service we provide to the leading companies in the electronic devices sector. In this context, we offer repair and service packages that best meet the needs and demands of consumers for devices such as smartphones and tablets, which have become one of the needs of daily life. While carrying out all these activities, our priority is to provide and maintain customer satisfaction by providing high quality and fast service. With Novo Mobil, our Ministry of Commerce approved renewal center, we examine second-hand devices with precision and perform all necessary cleaning and parts replacement processes and offer the best quality devices back to use. Thanks to this sustainable business model, we both extend the hardware life of the devices and contribute to the reduction of technological waste.We are constantly working, developing and developing with our expert team with a focus on carrying forward the expertise and knowledge we have gained since the day we were established at every stage and producing innovative projects using this information. In this process, by accurately analyzing customer demands and the needs of the market, we make our strategic planning

Incident timeline — mostly unverified

? — ?

Breach window unknown

Jun 29, 2023

Claim posted

No filing yet · watching

Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.

Claim → filing

Compliance clock

Not assessable

Tracked as a single-filing incident — the only disclosure on record for this event so far.Unverified claimView incident

Evidence ladder

Leak-site claimThis record

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filing

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.

No regulatory filing corroborates this yet — it is the attacker's own assertion. Watch this entity to be notified the moment a filing corroborates or contradicts it.

Source ceiling

  • actor name
  • victim claim
  • ransom/leak status
  • discovery date
  • materiality
  • notification
  • affected count
  • confirmed data types
  • compliance clock

The ✕ fields stay blank until a regulatory filing or victim disclosure lands.

About this groupFirst seen 2023-06-29

cyclops

According to ransomware.live, Cyclops emerged in May 2023 as a cross-platform RaaS operation targeting Windows, macOS, and Linux systems; it rebranded as "Knight" in August 2023 and its codebase was ultimately sold, with affiliates largely migrating to RansomHub.

7 victims claimed globally7 tracked hereFull profile →