Abtach Ltd. (later renamed Intersys Ltd.) in Pakistan was targeted by the Barracuda ransomware group, alleging involvement in fraud schemes impacting the US market and illicit opioid/fentanyl analogue trafficking routed through eWorldTrade. The attackers encrypted ESXi virtual machines and snapshots, encrypted employee computers’ files, exfiltrated 1.5 TB of data, and published/claimed access to documents and bank records tied to founder Azneem Bilwani. #UnitedStates#Pakistan
Incident Details
- Victim: Abtach Ltd.
- Sector: Not Found
- Country:
- Actor: Barracuda
- Source: http://uvm6hk4wwstfddja5z5htgtlehmfyflffijz6iozsuqyacyibzxefkqd.onion/leaks
- Discovered: 2026-09-23T19:20:51.283138+00:00
- Published: 2026-09-23T19:20:12.330662+00:00
Information
- The company was renamed Intersys Ltd. and was involved in fraud targeting the US, with employees charging fees for services that did not actually exist.
- The founder, Azneem Bilwani, was implicated in the illicit trafficking of synthetic opioids and fentanyl analogues supplied to the US market via the eWorldTrade marketplace.
- All virtual machines and snapshots on ESXi hypervisors were encrypted, along with files on employee computers.
- About 1.5 TB of data was exfiltrated from the infrastructure.
- The stolen material reportedly includes documents and bank records containing evidence of Azneem Bilwani’s illegal activities.
- The data is being offered for sale, with a severity level of HIGH and a listed price of $100,000.

Disclaimer: This post is based on public claims made by the ransomware group "Barracuda". I cannot confirm the accuracy of the information. However, I would be happy to share any official statement from the affected organization to provide clarification.