AT&S Listed by nokoyawa Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The AT&S Listed by nokoyawa Ransomware Group (reported July 29, 2023) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
In late July 2023, the ransomware group known as nokoyawa listed AT&S on its leak site, claiming the company had been hit in a ransomware attack that involved the exfiltration of internal files. Public reporting of the incident is sparse: the number of people affected remains unknown, and few operational details have been confirmed beyond the group's claim and the reported date of 29 July 2023.
For an organisation operating in the oil-and-gas and marine sectors, any confirmed or claimed compromise of internal material raises practical questions about what may have left the network and who might be exposed. What follows summarises only what is known so far and places it in context without speculation.
What happened
According to available records, AT&S was listed by the nokoyawa ransomware group on or around 29 July 2023. The listing asserts that internal files were exfiltrated as part of a ransomware attack. No public confirmation has established the precise date of initial access, the intrusion method, the volume of data taken, or whether encryption was successfully deployed against production systems. The number of individuals affected is recorded as unknown. Beyond the group's claim that internal files were removed, further technical or forensic detail has not been disclosed in the material available for this account.
Inside nokoyawa
Nokoyawa is a ransomware operation that became active in the public eye around early 2022. Like many contemporary groups, it has typically pursued a double-extortion model: encrypting systems while also copying data and threatening to publish or sell it if a ransom is not paid. The group has been observed using custom ransomware variants, sometimes with ties to earlier code families, and has listed victims across multiple sectors on dedicated leak sites. Its public posts generally serve as pressure tactics; a listing is a claim by the actors, not independent verification that every asserted file was in fact stolen or that negotiations occurred. No statements attributed to nokoyawa beyond the basic listing of AT&S and the assertion of internal-file exfiltration are part of the claimed record for this incident.
Who is AT&S?
AT&S was incorporated in Singapore in 2009 with the stated aim of supplying a full range of products and services to the oil-and-gas and marine industries, bringing together the capabilities of AquaTerra and SSH. At formation it positioned itself as a Singapore-based company of notable scale within those sectors. Organisations of this type routinely handle engineering drawings, project documentation, supplier and contractor records, operational schedules, and internal corporate files. Because such firms sit inside complex supply chains that support energy and maritime activity, a breach can have consequences that extend beyond a single corporate network to partners, contractors and, in some cases, individuals whose details appear in business records.
What was likely exposed
The only data category named in connection with the incident is “internal files” said to have been exfiltrated in a ransomware attack. No inventory of specific file types, databases or personal-data categories has been published. Companies operating in oil-and-gas and marine services commonly hold project files, technical specifications, commercial contracts, employee or contractor information, and correspondence. Whether any of those categories were among the material nokoyawa claims to possess has not been confirmed. Exact contents therefore remain unconfirmed; readers should treat any assumption about particular documents or personal records as speculative until official notification or further verified disclosure appears.
Why it matters
If internal files were copied, the practical risks depend on what those files contained. Business partners could face competitive or contractual exposure if pricing, designs or schedules were included. Individuals whose names, contact details or identification documents appeared in corporate records could encounter phishing, social-engineering or identity-related misuse. For AT&S itself, the episode creates operational, legal and reputational costs: incident response, possible regulatory notification duties, and the need to assess whether credentials or remote-access pathways remain compromised. Because the scale and precise contents are undisclosed, the full extent of downstream harm cannot yet be measured; the absence of confirmed numbers does not eliminate the need for vigilance among anyone who has dealt with the company.
Were you affected?
If you are a current or former employee, contractor, supplier or customer of AT&S, monitor account statements and be alert to unexpected messages that reference the company or request urgent action. Change passwords on any accounts that may have been reused in work contexts, and enable multi-factor authentication where it is available. Official notification from the organisation, if required and if your data was involved, remains the primary channel for Reported Details. As an additional check, you can run a free exposure scan of your email address to see whether it has already appeared in known breach datasets elsewhere.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Pea River Electric Cooperative Listed by nokoyawa Ransomware GroupMiescor Listed by nokoyawa Ransomware GroupStudio Domaine LLC Listed by nokoyawa Ransomware GroupRoman Catholic Diocese of Albany Listed by nokoyawa Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the AT&S Listed by nokoyawa Ransomware Group →
Publicly posted by nokoyawa — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.