Grupo Tersa
bd_b26cdbb4f21da536 · schema v1 · pii pii-v1
Full breach record for Grupo Tersa →Threat-actor claim — not a regulatory filing
This row is a claim by the ransomware group LockBit 3.x on its public extortion blog. It has not been validated by the victim or any regulator. Treat attribution and counts as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.
Sanctions caution: LockBit 3.x carries US sanctions exposure — OFAC has designated the group or its operators. Public reporting is permitted (informational-materials exemption, 50 U.S.C. § 1702(b)(3)) — but any payment or material support may violate sanctions. Consult counsel before engaging.
Source: Ransomware.live
Post text · scraped from the leak site
Greetings! Today we are posting here the new company, "Grupo TERSA". Company Description: Grupo TERSA was born from the dream of our Chairman and Founder Rodrigo Valle Hernández in 1982, which has now become the dream of a great team of workers...
Source provenance
- Source URL
- https://www.ransomware.live/id/Z3J1cG90ZXJzYS5jb20ubXhAbG9ja2JpdDM=
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 15, 2025
- Raw hash
- ec2412877ed9039d1f27d9fa3eb6d892e7b6763811559e97addee71c6d60db11
Reporting entity
- Name
- lockbit3norm: lockbit_3
Victim entity
- Name
- Grupo Tersanorm: grupo tersa
- Domain
- grupotersa.com.mx
- Industry
- Manufacturing
What this source establishes
- Source ceiling
- A leak-site claim can't tell us: discovery date · materiality · notification · affected count · confirmed data types · compliance clock. These stay blank until a regulatory filing or victim disclosure lands.
- Attack vector
- Ransomware· lockbit_3
- Threat actor
- LockBit 3.xExternalFinancial
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.