[Redacted by threat actor]
bd_dfb96bdad48aa645 · schema v1 · pii pii-v1
Threat-actor claim — not a regulatory filing
This row is a claim by the ransomware group Thegentlemen on its public extortion blog. It has not been validated by the victim or any regulator. Treat attribution and counts as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.
Source: Ransomware.live
Post text · scraped from the leak site
The entire infrastructure of a major regional retail grocery network—comprising approximately 80 grocery stores, about 40 liquor outlets, and roughly 50 pharmacies, along with its franchise operations—has been compromised, with all data stolen and encrypted. The targeted company reports an annual revenue of $1.4 to $1.8 billion (according to various 2025 estimates). The exfiltrated data includes all insurance payouts (even detailed records of payouts to families of deceased employees, listing cause of death and amounts paid), complete personnel records for all employees and executives (containing SSN, date of birth, full name, address, passport details, and W-9 forms), every financial document, records of active deals and income/expenses, as well as all documentation and insurance records for the company's movable and immovable property. http://i2ohjeeqe37jre4f2u7pyq73cbm6lecumdxapkvrlryna6rc3it4zsid.onion (your key in Tox Chat)
Source provenance
- Source URL
- https://www.ransomware.live/id/KioqKiouY29tQHRoZWdlbnRsZW1lbg==
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Dec 12, 2025
- Raw hash
- 1df11cf38628361a566964ad3f0882c77a61b0c4a5c67d6e3ac0fd178770b61b
Reporting entity
- Name
- thegentlemen
Victim entity
- Name
- [Redacted by threat actor]norm: redacted-4c561b32
- Industry
- Retail & Consumerllm
What this source establishes
- Source ceiling
- A leak-site claim can't tell us: discovery date · materiality · notification · affected count · confirmed data types · compliance clock. These stay blank until a regulatory filing or victim disclosure lands.
- Attack vector
- Ransomware· thegentlemen
- Threat actor
- ThegentlemenExternalFinancial
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.