Ransom! LT Group / Fortune Tobacco Corp (AUG-2026)

Ransom! LT Group / Fortune Tobacco Corp (AUG-2026)
Deadlock ransomware activity targeted LT Group / Fortune Tobacco Corp in the Philippines (PH), where 14,836 files totaling 27 GB were allegedly compromised after the victim ignored extortion messages for 72 hours. The attackers leaked samples including passport (MRZ) data, PNB/Holco USD bank statements, BIR/eFPS credentials, and promissory notes tied to Eton Properties (PHP 2.53B debt), with the impact disclosed as “Full leak: August 18.” #Philippines

Incident Details

Information

  • The group ignored our messages for 72 hours, so we are now publishing the breach details.
  • Data leaked includes 107 passports with MRZ data, 1,712 bank statements, 212 promissory notes, and 231 BIR/eFPS credentials.
  • The promissory notes relate to Eton Properties and total PHP 2.53 billion in debt.
  • Sample files include Passport_Johnny_Tan.pdf, Holco_USD_Statement.pdf, and Eton_Debt_212.pdf.
  • The full leak is scheduled for August 18.
  • Contact was made using the Session ID provided in emails.
  • The demand is to pay for the data or pay for its permanent deletion, otherwise the full dump will be made public.

Disclaimer: This post is based on public claims made by the ransomware group "Deadlock". I cannot confirm the accuracy of the information. However, I would be happy to share any official statement from the affected organization to provide clarification.

monitored by: ransomware.live