Ransom! ANG BROTHERS (M&E) PTE. LTD. (P1)

Ransom! ANG BROTHERS (M&E) PTE. LTD. (P1)

Victim ANG BROTHERS (M&E) PTE. LTD. (P1), a Singapore-based company specializing in plumbing, heating, and air-conditioning, has been targeted by the threat actor nova, resulting in the theft of 3TB of sensitive data that will be leaked in 15 parts over 10 days. The company is advised to follow the provided recovery instructions to restore encrypted files, with a 1GB sample of data available as proof of breach, impacting Singapore.

Incident Details

  • Victim: ANG BROTHERS (M&E) PTE. LTD. (P1)
  • Country: SG
  • Actor: nova
  • Source: http://pifk3xu3vad6cuxsjll4qjomyaaaoyvnyqppro75pazadzctrrvpdnyd.onion/#ang-brothers-m-e-pte-ltd-p1
  • Discovered: 2025-11-15 15:36:16.970764
  • Published: 2025-11-15 15:35:26.619650

Information

  • The company, ANG BROTHERS (M&E) PTE. LTD., is a Singapore-based Exempt Private Company Limited by Shares, incorporated on 22 July 2002.
  • Its registered office is located in the SHUN LI INDUSTRIAL PARK estate.
  • The company has been operating for 23 years and is currently in active operation.
  • The principal activities include plumbing, non-electric heating, and air-conditioning services, with steam and air-conditioning supply as secondary activities.
  • The stolen data comprises approximately 3TB unzipped and 1.05TB zipped files, including millions of documents and files.
  • The data will be leaked in 15 parts, with each part containing 250GB and leaked over 10 days.
  • The company has been in contact regarding recovery efforts through network-guided procedures to decrypt files and restore systems.
  • A 1GB sample of the leaked data will be provided for assessment.
  • The leaked data contains highly sensitive information and various other critical data.
  • Company profile: https://www.sgpbusiness.com/company/Ang-Brothers-Me-Pte-Ltd.

Disclaimer: This post is based on public claims made by the ransomware group "nova". I cannot confirm the accuracy of the information. However, I would be happy to share any official statement from the affected organization to provide clarification.

monitored by: ransomware.live