ANG BROTHERS (M&E) PTE. LTD. (P1) Listed by nova Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
On 15 November 2025, ANG BROTHERS (M&E) PTE. LTD. was listed by the nova ransomware group, which claims to have exfiltrated internal files. Individuals connected to the company should review their exposure and take protective steps.
Inside the incident
The only confirmed public record is the November 15, 2025 listing by nova. The group states that it exfiltrated internal files in a ransomware operation and claims to hold approximately 3 TB of uncompressed data and 1.05 TB of compressed archives containing millions of documents and files. It further claims the material will be released in 15 parts. No independent verification of the volume, contents, or encryption status has been made public. The date of the underlying intrusion, the method of initial access, and any ransom demand or payment remain undisclosed.
The group behind it: nova
Nova is a ransomware operator that follows a double-extortion model: it encrypts systems and also removes copies of data before demanding payment. The group maintains a public leak site where it posts the names of organizations it claims to have targeted, along with samples or descriptions of stolen material. This approach is intended to increase pressure on victims who decline to pay. Nova has appeared in multiple prior listings involving companies in construction, manufacturing, and professional services, though each claim requires separate verification.
Who is ANG BROTHERS (M&E) PTE. LTD.?
ANG BROTHERS (M&E) PTE. LTD. is an exempt private company limited by shares incorporated in Singapore on 22 July 2002. Its registered office is located in the Shun Li Industrial Park estate. The company remains active after more than two decades and lists plumbing and heating (non-electric) as its primary activity, with air-conditioning and steam supply as secondary activities. Firms in this sector manage mechanical and electrical installation projects for buildings, which involves coordination with clients, subcontractors, and regulatory bodies.
What was likely exposed
The listing refers only to “internal files exfiltrated in ransomware attack.” The precise categories of information have not been disclosed. Organizations of this type commonly maintain employee records, client contracts, project specifications, equipment inventories, financial documentation, and correspondence with suppliers and regulators. Whether any of these categories are present in the claimed data set cannot be confirmed from the available information.
What's at stake
If personal details such as names, identification numbers, or contact information are included among the files, affected individuals could face risks of identity misuse or targeted scams. For the company, publication of project files or internal communications could affect client relationships and ongoing work. The absence of confirmed data categories means the scale of these risks cannot yet be quantified.
What to do if you're exposed
Individuals who have worked with or for the company should monitor bank and credit accounts for unusual activity and consider placing fraud alerts with credit bureaus. Changing passwords for any accounts linked to the organization and enabling multi-factor authentication are immediate steps. Readers can run a free exposure scan of their email address against known breach data sets to check whether their information has appeared in previously published collections.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
ANG BROTHERS (M&E) PTE. LTD. (P3) Listed by nova Ransomware GroupANG BROTHERS (M&E) PTE. LTD. (P2) Listed by nova Ransomware GroupLCM Construção e Comércio S/A Listed by nova Ransomware GroupNational Health Insurance Management Authority Listed by nova Ransomware GroupLatest breaches
Publicly posted by nova — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.