LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › CILI Listed by blacknevas Ransomware Group

HIGH severityUnverified claimHow we verify

CILI Listed by blacknevas Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·July 2, 2025
CILI Listed by blacknevas Ransomware Group

Reported July 2, 2025.

HIGH
Severity
July 2, 2025
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

CILI was listed by the blacknevas ransomware group on July 02, 2025, after internal files were exfiltrated in a ransomware attack that affected an undisclosed number of people. Individuals connected to the organization should check whether their information was exposed and take appropriate protective steps.

Severity & verification
HIGH severityUnverified claim
Contact / identity PII exposed.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

On July 2, 2025, the restaurant operator CILI was listed by the ransomware group blacknevas. Public reporting indicates that internal files were exfiltrated during a ransomware attack. The number of people affected remains unknown, and many operational details of the incident have not been disclosed.

CILI is linked to the Čili restaurant chain operating in Lithuania and Latvia. A listing of this kind raises practical concerns for customers and staff because restaurant groups commonly process orders, contact details and payment information. The listing itself is a claim by the group and has not been independently confirmed in the available record.

Inside the incident

According to the reported summary, CILI, associated with the domain cili.lt, was listed by blacknevas after a ransomware attack in which internal files were exfiltrated. The date of the listing is given as July 2, 2025. No confirmed figures for the volume of data taken, the precise method of initial access, or the duration of any network presence have been released. The number of individuals potentially affected is listed as unknown.

The available account states that a database containing customer data was among the material claimed to be in the attackers’ possession. Beyond the description of internal files and that claimed database, further technical specifics such as encryption status of systems, ransom demands, or negotiation outcomes are not part of the public record. The incident is therefore known primarily through the group’s leak-site listing rather than through detailed forensic disclosure by the organisation or independent investigators.

The group behind it: blacknevas

blacknevas is a ransomware operation that follows the double-extortion model common among contemporary groups: data is stolen before systems are encrypted, and victims are threatened with public release if a ransom is not paid. The group maintains a leak site on which it posts victim names and, in some cases, sample files or descriptions of the material it claims to hold. Listings of this type are public assertions by the actors and do not automatically constitute verified proof of every claimed detail.

Public knowledge of blacknevas indicates that it has previously targeted organisations across multiple sectors, using standard ransomware techniques such as phishing, exploitation of remote-access services, or compromised credentials to gain entry. Once inside a network, operators typically move laterally, identify valuable data stores, exfiltrate selected files, and then deploy encryption. The group’s communications and leak-site posts are the primary source of its claims; independent confirmation of those claims is often limited or delayed. In the present case, the listing of CILI is treated as an unverified claim by blacknevas unless and until additional corroboration appears.

Who is CILI?

CILI refers to the Čili restaurant chain, which operates in Lithuania and Latvia. The business began as a pizza restaurant and later expanded into bistros, traditional Lithuanian-style restaurants, Chinese restaurants, coffee shops and drive-ins. Its website, cili.lt, allows customers to order pizza online, and a mobile application offers ordering with exclusive discounts.

Restaurant chains of this scale routinely manage customer accounts, delivery addresses, order histories and payment processing. They also hold internal operational files covering staff, suppliers and business systems. A ransomware incident affecting such an organisation is consequential because it can disrupt ordering platforms, expose customer contact and transaction data, and create ongoing risk of fraud or identity misuse for individuals whose information was stored. The chain’s multi-country footprint in the Baltic region means any confirmed exposure could affect residents of both Lithuania and Latvia.

What data was at risk

The facts state that internal files were exfiltrated in the ransomware attack. The group’s listing further claims possession of a database containing customer data, addresses, email addresses, mobile phone numbers, shopping history and banking-card information. These data types are presented as the group’s assertion; the exact contents of any stolen material remain unconfirmed by independent sources.

Organisations in the restaurant and food-service sector typically retain customer profiles for loyalty programmes and online ordering, delivery addresses, contact details, purchase records and payment-card tokens or related billing data. They also store internal documents such as employee records, supplier contracts and operational files. Because the precise inventory of what was taken has not been publicly verified, it is not possible to state with certainty which of these categories were actually exposed. The reported description should therefore be understood as the attackers’ claim rather than as an audited inventory.

What's at stake

For individuals, the primary risks are misuse of contact details for phishing or social-engineering attempts, and potential fraud if payment-card or banking information was among the material taken. Even partial customer records can enable targeted scams that reference real order histories or addresses, increasing their credibility. Shopping histories and phone numbers can also be combined with other leaked data sets to build more complete profiles of individuals.

For the organisation, the consequences include operational disruption while systems are restored, potential regulatory scrutiny under data-protection rules applicable in Lithuania and Latvia, and reputational damage that may affect customer trust in online ordering channels. Because the number of affected people is unknown and the full scope of the exfiltration is unconfirmed, both the human and organisational impact remain difficult to quantify precisely at this stage. The absence of confirmed figures does not eliminate the need for vigilance among customers who have used Čili’s website or mobile app.

Were you affected?

If you have ordered from Čili via its website or mobile application, or if you have otherwise supplied personal or payment details to the chain, treat the possibility of exposure as real until more information becomes available. Monitor bank and card statements for unfamiliar transactions, be alert to unexpected emails or messages that reference recent orders, and consider changing passwords used on the ordering platforms if they are reused elsewhere. Enable multi-factor authentication on any accounts that support it.

Readers can also run a free exposure scan of their email address to check whether that address has already appeared in known breach data sets. Such a check does not prove or disprove involvement in this specific incident, but it provides a practical starting point for assessing personal risk and deciding on further protective steps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyCILI security record
87/100
DoxxScan™ · Low doxx risk
B 80Good record

1 reported incident on record.

See CILI’s full breach history →

More recent breaches

CHABAA BANGKOK Listed by blacknevas Ransomware GroupJuly 22, 2025Applied LNG Listed by blacknevas Ransomware GroupDecember 22, 2025Paramount Health Services & Insurance TPA Pvt. Ltd Listed by blacknevas Ransomware GroupNovember 19, 2025Trojan Construction & Holding Group Listed by blacknevas Ransomware GroupOctober 21, 2025

Latest breaches

Read GalaxyWarden’s full analysis of the CILI Listed by blacknevas Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by blacknevas — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram