Ransom! Mat Bao Corporation (OCT-2026)

Ransom! Mat Bao Corporation (OCT-2026)
Mat Bao Corporation (VN) reported a ransomware incident attributed to the rhysida threat actor, impacting approximately 746,108 files across 106.8 GB that included government inspection materials, corporate core business-registration records, and personal data such as CCCD national ID cards and employee passports. The claimed data exposure also includes regulator correspondence with VN authorities (VNNIC, NEAC) and litigation/operations material, including the VINASEED dispute and internal investigation mail. #Vietnam

Incident Details

  • Victim: Mat Bao Corporation
  • Sector: Technology
  • Country: VN
  • Actor: rhysida
  • Source: http://rhysidafohrhyy2aszi7bm32tnjat5xri65fopcxkdfxhi4tidsg7cad.onion/archive.php?company=280
  • Discovered: 2026-10-02T20:04:32.336783+00:00
  • Published: 2026-10-02T20:04:06.819776+00:00

Information

  • Offers domain registration, cloud hosting, professional email solutions, and cloud server storage.
  • 746,108 files were compromised, totaling 106.8 GB of data.
  • Government inspection materials were exposed, including NEAC inspection decision No. 61/QD dated 29.04.2025, along with working minutes naming state inspectors and company staff through December 2025.
  • Corporate core documents were leaked, including business registration records with the owner’s signature, shareholder records, and tax commitments from January 2026.
  • Personal data was exposed, including national ID cards, employee passports with signatures, and staff lists.
  • Regulator correspondence was leaked, including communications with VNNIC, NEAC, and the Government Cipher Committee, including references to RSA-1024 token vulnerabilities.
  • Litigation and operational materials were exposed, including the VINASEED dispute, internal investigations, and operations department emails.

Disclaimer: This post is based on public claims made by the ransomware group "rhysida". I cannot confirm the accuracy of the information. However, I would be happy to share any official statement from the affected organization to provide clarification.

monitored by: ransomware.live