DisclosureLens
GLOBALMalwareAgriculture & FoodAgricultureRansomwareShadowbyt3$Shadowbyt3Ransom DemandedActor NamedData Leak ThreatenedData PublishedHigh

Sinar Mas Agribusiness and Food Golden Agri-Resources)

bd_9a1e6f8d86dc487e · schema v1 · pii pii-v2

Severity

High

Discovered

Filed

Aug 25, 2026

To disclose

Affected

Not disclosed

Confidence

50%
Full breach record for Sinar Mas Agribusiness and Food Golden Agri-Resources)

Threat-actor claim — not a regulatory filing

This row is a claim by the ransomware group Shadowbyt3$ on its public extortion blog. It has not been validated by the victim or any regulator. Treat attribution and counts as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.

Group activity: Agriculture and Food ProductionDiscovered: 2026-08-25

Source: Ransomware.live

Post text · scraped from the leak site

We Breached This company a few months ago. we stole 375.66MB. mirror 1: https://anonfilesnew.com/s/4t-mBJg9wMy More info is on darkforums.ru about this leak.

Incident timeline — mostly unverified

? — ?

Breach window unknown

Aug 25, 2026

Claim posted

No filing yet · watching

Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.

Claim → filing

Compliance clock

Not assessable

Tracked as a single-filing incident — the only disclosure on record for this event so far.Unverified claimView incident

Evidence ladder

Leak-site claimThis record

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filing

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.

No regulatory filing corroborates this yet — it is the attacker's own assertion. Watch this entity to be notified the moment a filing corroborates or contradicts it.

Source ceiling

  • actor name
  • victim claim
  • ransom/leak status
  • discovery date
  • materiality
  • notification
  • affected count
  • confirmed data types
  • compliance clock

The ✕ fields stay blank until a regulatory filing or victim disclosure lands.

About this groupFirst seen 2026-02-17

shadowbyt3$

According to ransomware.live, ShadowByt3$ is a ransomware-as-a-service group first observed in October 2025, using multi-method extortion and communicating via Telegram and Tox, with a very small confirmed victim list suggesting it remains in early-stage operation.

31 tracked hereFull profile →