Belfor
bd_8da6188f83ac7920 · schema v1 · pii pii-v1
Full breach record for Belfor →Threat-actor claim — not a regulatory filing
This row is a claim by the ransomware group INC Ransom on its public extortion blog. It has not been validated by the victim or any regulator. Treat attribution and counts as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.
Source: Ransomware.live
Post text · scraped from the leak site
BELFOR (Asia) Pte Ltd, Singapore. RecoveryPro Ltd, Japan. Country list: Singapore, Japan, Korea, Taiwan, Thailand, Malaysia. Total Data: 430GB Data: Confidential (Classified) - non-disclosure agreements (NDA's), Personal scan passports, Employee Privacy, Employment contracts, Employment Records, Health Information. Finance Department - Salary & Bonus structures, Internal audit reports, Insurance contracts & payments, Payroll Reports, Benefits & pension details, Internal investigations, Partners agreements, Balance sheets, Budget reports, Credit agreements, Tax filings, Marketing plans. IT Department - IT network infrastructure, Research and development data, SDLC documentation. Other - All projects report & files, Buildings drawings, Object Photo, Photo of damages, Object plans, a lot of internal documentation. Clients: Mitsubishi, Samsung, Toyota, Kawasaki Motors, Sony Technology, Fujifilm Business Innovation, Siemens, Seiko, Nissan and many other. Full data release coming soon!!!
Source provenance
- Source URL
- https://www.ransomware.live/id/QkVMRk9SQGluY3JhbnNvbQ==
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 26, 2026
- Raw hash
- 4988ab0dd3ac13da8a03eaf84e522f038a8ef775dc8449a74c20ad5e22842fca
Reporting entity
- Name
- incransomnorm: inc_ransom
Victim entity
- Name
- Belfornorm: belfor
- Industry
- Professional Services
What this source establishes
- Source ceiling
- A leak-site claim can't tell us: discovery date · materiality · notification · affected count · confirmed data types · compliance clock. These stay blank until a regulatory filing or victim disclosure lands.
- Attack vector
- Ransomware· inc_ransom
- Threat actor
- Inc RansomExternalFinancial
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.