Welcome to Rocket!
bd_f74d9efb20f9f1ed · schema v1 · pii pii-v1
Full breach record for Welcome to Rocket! →Threat-actor claim — not a regulatory filing
This row is a claim by the ransomware group Cactus on its public extortion blog. It has not been validated by the victim or any regulator. Treat attribution and counts as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.
Source: Ransomware.live
Post text · scraped from the leak site
<p>Convenience Stores, Gas Stations & Liquor Stores.<\/p><p>“Founded in 1955 and based in Long Beach, California, we are one of the largest independent owners, suppliers and operators of gas stations and convenience stores in the Western United States. We have over 3,500 Team Members in more than 450 locations spread across California, Oregon, Washington and Colorado and we're still growing!”<\/p><p>Website: https://rocketstores.com/<\/p><p>Revenue : $738.9M<\/p><p>Address: 4130 Cover St, Long Beach, California, 90808, United States<\/p><p>Phone Number: (844) 586-4833<\/p><p><mark class="marker-yellow"><strong>Download link #1:<\/strong><\/mark> <a href="https://6wuivqgrv2g7brcwhjw5co3vligiqowpumzkcyebku7i2busrvlxnzid.onion/ROCKETSTORES/PROOF/">https://6wuivqgrv2g7brcwhjw5co3vligiqowpumzkcyebku7i2busrvlxnzid.onion/ROCKETSTORES/PROOF/<\/a><br><br><mark class="marker-yellow"><strong>Mirror:<\/strong><\/mark> <a href="https://cactus5dqnqkppa5ayckiyk6dttpqwczdqphv5mxh4dkk5ct544q5aad.onion/ROCKETSTORES/PROOF/">https://cactus5dqnqkppa5ayckiyk6dttpqwczdqphv5mxh4dkk5ct544q5aad.onion/ROCKETSTORES/PROOF/<\/a><\/p><p><mark class="marker-yellow"><strong>DATA DESCRIPTIONS:<\/strong><\/mark> Personal identifiable information, corporate internal data, contracts, NDAs, financial data\payroll, legal documents, employees and executives personal data, corporate confidential and personal correspondence, etc.<\/p><p><img src="/uploads/2024_Ryan_Contract_Apro_fully_executed_16ca910a91.png" alt="2024 Ryan Contract Apro fully executed.png"><img src="/uploads/incident_report_3_3_23_9b3e1a0e3e.png" alt="incident report 3-3-23.png"><img src="/uploads/Project_Sunshine_CIP_confidential_do_not_share_or_distribute_77785b7491.png" alt="Project Sunshine_CIP_confidential do not share or distribute.png"><img src="/uploads/2025_02_11_Settlement_Demand_Letter_and_Complaint_usps_2_18_aabf72c3af.png" a
Source provenance
- Source URL
- https://cactusbloguuodvqjmnzlwetjlpj6aggc6iocwhuupb47laukux7ckid.onion/posts/ROCKETSTORES
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 26, 2025
- Raw hash
- b0f9cbaec2b315c0d44e13b749f7ed9da1f28977f28aa7ec2026acd9c0120620
Reporting entity
- Name
- cactus
Victim entity
- Name
- Welcome to Rocket!norm: welcome to rocket
- Domain
- rocketstores.com
- Industry
- Retail & Consumerllm
What this source establishes
- Source ceiling
- A leak-site claim can't tell us: discovery date · materiality · notification · affected count · confirmed data types · compliance clock. These stay blank until a regulatory filing or victim disclosure lands.
- Attack vector
- Ransomware· cactus
- Threat actor
- CactusExternalFinancial
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.