ELTEK Group (eltekgroup.com) Listed by fog Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
ELTEK Group (eltekgroup.com) was listed by the fog ransomware group on January 24, 2025, after internal files were exfiltrated in a ransomware attack. An undisclosed number of people may have been affected; anyone connected to the organisation should check official updates and follow any guidance provided.
On January 24, 2025, the ransomware group known as fog listed ELTEK Group (eltekgroup.com) on its leak site, claiming responsibility for a ransomware attack that involved the exfiltration of internal files totaling 13 GB. The number of people affected remains unknown, and public detail on the incident is limited to this listing and the reported volume of data. The claim has not been independently confirmed in available records, but the appearance of a company on a ransomware group's site raises immediate questions about potential exposure of internal materials and the broader implications for those connected to the organization.
Such listings form part of the double-extortion model common among ransomware operators, in which data is stolen before systems are encrypted and then used as leverage. For ELTEK Group and anyone whose information may have been among the files, the core issue is the claimed claim of exfiltration rather than any verified public dump of the material itself.
What happened
According to the available record, ELTEK Group was listed by the fog ransomware group on January 24, 2025. The group claims that internal files were exfiltrated during a ransomware attack and that the volume of data taken amounts to 13 GB. No further technical details—such as the initial access vector, the duration of the intrusion, the specific systems affected, or any encryption of operational environments—have been disclosed in the public facts. The number of individuals whose data may have been involved is listed as unknown. The listing itself constitutes the primary public indicator of the incident; whether the data has been released more widely or remains held by the group is not stated.
Public reporting on the matter is confined to the group's claim and the associated data-volume figure. No independent confirmation of the breach's success, the authenticity of the files, or any subsequent negotiation has been provided in the source material. As with many ransomware listings, the information available is therefore limited to what the threat actor has chosen to assert.
Who is fog?
Fog is a ransomware operation that has been active in the public threat landscape since approximately mid-2024. Like many contemporary groups, it follows a double-extortion model: operators encrypt victim systems while simultaneously exfiltrating data, then threaten to publish or sell the stolen material if a ransom is not paid. The group typically posts victim names and sample file listings on a dedicated leak site to apply pressure. Public reporting has associated fog with attacks across multiple sectors, often using common initial-access techniques such as compromised credentials or exploitation of unpatched remote services, though specific tooling and affiliates can vary between campaigns.
The group has not issued detailed public statements beyond the standard leak-site claims for most of its listed victims. In the case of ELTEK Group, the facts record only the listing itself and the assertion that 13 GB of internal files were taken. No additional claims unique to this victim—such as particular file categories, ransom demands, or deadlines—appear in the provided record. Fog's activity is monitored by cybersecurity researchers as part of the broader ransomware ecosystem, but each listing remains an unverified claim until corroborated by the victim organization or independent evidence.
ELTEK Group (eltekgroup.com) and its sector
ELTEK Group operates under the domain eltekgroup.com and is publicly known as a company specializing in power electronics and energy systems, particularly solutions for telecommunications infrastructure, data centers, and industrial applications. Organizations of this type typically design, manufacture, and support power conversion equipment, battery systems, and related monitoring platforms used by network operators and critical facilities. Their day-to-day operations involve engineering documentation, supply-chain records, customer contracts, employee information, and technical specifications that support global deployments.
A ransomware incident affecting a firm in this sector carries weight because power and energy-system providers sit at the intersection of industrial technology and critical infrastructure support. Even when the precise operational impact is undisclosed, the presence of internal files among claimed exfiltrated material raises the possibility that proprietary designs, customer project details, or business correspondence could be involved. The sector's reliance on specialized knowledge and long-term client relationships means that any unauthorized access to internal repositories can affect both competitive position and the trust of partners who depend on the company's systems.
What data was at risk
The facts state that internal files were exfiltrated in the ransomware attack and that the volume claimed is 13 GB. No more granular breakdown—such as whether the files included employee records, customer data, financial documents, source code, or technical drawings—is provided. The number of people affected is explicitly listed as unknown. Because the exact contents remain unconfirmed, it is not possible to state with certainty which categories of information were present.
Organizations operating in power electronics and industrial technology commonly hold engineering schematics, product documentation, supplier contracts, human-resources files, and correspondence with telecommunications or data-center clients. Any of these could theoretically fall under the broad description of "internal files." Until the company or independent analysis provides further detail, however, the precise nature of the 13 GB remains an open question. Readers should treat the data types as unconfirmed beyond the general claim of internal-file exfiltration.
What's at stake
For individuals whose information may have been among the files, the primary risks include potential misuse of personal or professional details if those materials later surface. Even without confirmed identity documents, internal correspondence or contact lists can enable targeted phishing or social-engineering attempts. For the organization itself, the stakes involve possible exposure of proprietary technical information, disruption of ongoing projects, and the need to assess whether any operational systems were encrypted or otherwise impaired. Reputational considerations also arise once a company appears on a ransomware leak site, regardless of whether the full data set is ever published.
Because the number of affected people is unknown and the file contents are not itemized, the concrete impact cannot be quantified from public facts alone. The 13 GB figure indicates a non-trivial volume of material, yet without confirmation of release or further analysis, the real-world consequences remain potential rather than demonstrated. Both the company and any connected parties face the practical task of determining exposure and implementing appropriate monitoring.
If your data was in this claimed breach
If you have a past or present relationship with ELTEK Group—as an employee, contractor, customer, or supplier—consider taking basic protective steps. Monitor financial and email accounts for unusual activity, enable multi-factor authentication wherever available, and treat unexpected messages that reference the company with caution. Change passwords on any accounts that may have shared credentials with work systems, and remain alert for phishing that could leverage knowledge of internal projects or contacts.
Because the exact contents of the claimed 13 GB are unconfirmed, it is not yet possible to know whether any particular individual's data is involved. Readers can run a free exposure scan of their email address to check whether that address has already appeared in known breach data sets. Such a scan provides one additional data point and does not replace ongoing vigilance, but it can help determine whether further personal information has circulated more widely.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Engikam Listed by fog Ransomware GroupBizcode Listed by fog Ransomware GroupGrupo Baston Aerossol (baston.com.br) Listed by fog Ransomware GroupKlesk Metal Stamping Co (kleskmetalstamping.com) Listed by fog Ransomware GroupLatest breaches
Publicly posted by fog — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.