egco.com Listed by lockbit3 Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The egco.com Listed by lockbit3 Ransomware Group (reported November 5, 2023) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
On November 05, 2023, egco.com — the online presence of Electricity Generating Public Company Limited, known as EGCO Group — was listed by the ransomware group lockbit3. Public reporting states that internal files were exfiltrated in a ransomware attack. The number of people affected remains unknown, and wider technical details have not been released.
For an electricity generator of this scale, any confirmed or claimed compromise of internal material raises practical questions about operational data, employee and partner records, and the downstream effects on people whose information may have been held in those systems. What is firmly established so far is limited to the listing itself and the description of internal-file exfiltration.
Breaking down the breach
According to the available record, egco.com was listed by lockbit3 on or about November 05, 2023. The reported summary identifies the organisation as Electricity Generating Public Company Limited — EGCO Group. The only data description provided is that internal files were allegedly exfiltrated in a ransomware attack. No figure for affected individuals has been published, no attack vector or initial-access method has been disclosed, and no confirmation of ransom payment, negotiation, or full data release appears in the public facts.
Because the listing originates from the threat actor’s leak site, it stands as a claim by lockbit3 rather than an independently verified statement of every asserted detail. Organisations in this position commonly face pressure from double-extortion tactics — encryption of systems paired with the threat of publishing stolen data — yet the precise sequence of events inside EGCO’s environment remains undisclosed.
Who is lockbit3?
Lockbit3 is the name associated with a long-running ransomware operation that functions as a ransomware-as-a-service (RaaS) enterprise. Affiliates gain access to victim networks, deploy the LockBit encryptor, and exfiltrate data before encryption in many cases. The group maintains a Tor-based leak site where it names victims and, if payment is not made, publishes samples or larger archives of stolen material. LockBit has been among the most prolific ransomware brands in recent years, targeting organisations across energy, manufacturing, professional services and the public sector worldwide.
Typical tactics include exploitation of exposed remote-access services, stolen credentials, and unpatched vulnerabilities, followed by lateral movement, privilege escalation, data staging and exfiltration, then deployment of ransomware. The group’s public communications are designed to maximise pressure on the named organisation. In this incident, lockbit3’s listing of egco.com constitutes the group’s claim that it held and could release internal EGCO material; independent corroboration of the full scope is not contained in the public facts.
Who is egco.com?
egco.com is the web domain of Electricity Generating Public Company Limited, commonly called EGCO Group. EGCO is a major independent power producer headquartered in Thailand, with interests in electricity generation from conventional and renewable sources and related energy businesses in multiple countries. Companies of this type routinely manage engineering and operational data, commercial contracts, employee and contractor records, supplier information, regulatory filings, and financial documentation.
A breach or claimed breach at an electricity-generating group is consequential because the sector underpins critical infrastructure. Even when the immediate impact is confined to corporate files rather than generation control systems, the exposure of internal documents can affect employees, business partners, and the organisation’s ability to operate with confidence. Public detail does not establish that generation assets themselves were disrupted; the reported focus is internal-file exfiltration.
The information in question
The facts name the exposed material only as “internal files exfiltrated in a ransomware attack.” No inventory of file types, no count of documents, and no confirmation of specific categories such as personal data, credentials, or technical schematics have been published. Exact contents therefore remain unconfirmed.
Organisations in the power-generation sector typically hold human-resources files, vendor and joint-venture contracts, project documentation, financial records, and internal communications. Any of those categories could be present among “internal files,” but stating that particular data sets were taken would exceed what the record supports. Until EGCO or independent investigators publish a clearer accounting, the prudent position is that the precise composition of the exfiltrated material is unknown.
What's at stake
For individuals whose data may have been among the internal files, the concrete risks include possible misuse of personal or contact information, targeted phishing that references real internal details, and longer-term identity or credential abuse if such data were present. Because the number of affected people is unknown and the data types are not itemised, those risks cannot yet be quantified.
For EGCO Group the stakes include operational disruption if systems were encrypted, reputational and regulatory scrutiny, potential contractual or disclosure obligations, and the cost of investigation, remediation and customer or partner notification. Energy-sector entities also face heightened attention from authorities concerned with critical-infrastructure resilience. None of these outcomes is established as having already materialised beyond the fact of the lockbit3 listing and the reported exfiltration of internal files; they are the ordinary consequences that follow such an incident.
Were you affected?
If you are a current or former employee, contractor, supplier or partner of EGCO Group, treat the possibility of exposure seriously until more detail emerges. Practical first steps include:
- Monitor official statements from EGCO Group for any confirmation of affected data categories or notification processes.
- Be alert to unexpected emails, calls or messages that reference EGCO internal matters; verify them through known channels before responding or clicking links.
- Change passwords on work-related and personal accounts that may have shared credentials, and enable multi-factor authentication where available.
- Review financial and credit activity for unusual behaviour if you believe personal identifiers could have been involved.
- Run a free exposure scan of your email address to check whether it has already appeared in known breach data sets.
Public information on this incident remains limited. Further clarity will depend on disclosures from the organisation or from independent analysis. Until then, measured caution and basic account hygiene are the most useful responses.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
hendelsinc.com Listed by dispossessor Ransomware Groupgoldwind.com Listed by lockbit3 Ransomware Groupdena.de Listed by lockbit3 Ransomware Grouppetrotec.com.qa Listed by lockbit3 Ransomware GroupLatest breaches
Read GalaxyWarden’s full analysis of the egco.com Listed by lockbit3 Ransomware Group →
Publicly posted by lockbit — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.