LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › ExcelPlast Tunisie Listed by orca Ransomware Group

HIGH severityUnverified claimHow we verify

ExcelPlast Tunisie Listed by orca Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·September 16, 2024
ExcelPlast Tunisie Listed by orca Ransomware Group

Reported September 16, 2024.

HIGH
Severity
September 16, 2024
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

ExcelPlast Tunisie has been listed by the orca ransomware group following an attack in which internal files were exfiltrated; the breach was disclosed on 16 September 2024. Anyone associated with the company should check their exposure and take appropriate steps to protect their information.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Ransomware groups continue to target manufacturers and mid-sized industrial firms across regions, using double-extortion tactics that combine encryption with data theft and public leak-site pressure. In this landscape, listings of companies in plastics and related materials production have become a recurring feature of threat-actor activity, often surfacing with limited independent confirmation of scale or impact.

On 16 September 2024, ExcelPlast Tunisie was listed by the ransomware group known as orca. Public reporting indicates that internal files were claimed to have been exfiltrated in a ransomware attack. The number of people affected remains unknown, and further operational details have not been disclosed. The listing itself is a claim by the group; independent verification of the full extent of any compromise has not been publicly established.

Breaking down the breach

According to available records, ExcelPlast Tunisie appeared on a listing associated with the orca ransomware group on 16 September 2024. The reported summary states that internal files were exfiltrated in a ransomware attack. No public figure has been given for the volume of data, the number of systems involved, or the precise method of initial access. Timing of the intrusion itself, beyond the listing date, is undisclosed. The number of people affected is recorded as unknown. These are the only concrete elements provided in the public breach record; claims of broader compromise rest on the group’s own listing and have not been independently detailed.

The group behind it: orca

Orca is a ransomware actor that has operated with a double-extortion model common among contemporary groups: encrypting systems while also stealing data and threatening to publish it on a dedicated leak site if demands are not met. Like many such operators, orca has historically focused on mid-market and industrial organisations, using public listings to increase pressure. The group’s typical tactics include initial access through common vectors such as phishing or exposed remote services, followed by lateral movement, data staging, and encryption. Prior activity attributed to orca has involved listings of companies across manufacturing, logistics, and professional services, though each incident must be assessed on its own evidence. In the case of ExcelPlast Tunisie, the group claims the organisation as a victim and asserts that internal files were taken; that claim has not been independently confirmed in the available public record, and no specific statements by orca beyond the listing itself are documented here.

ExcelPlast Tunisie and its sector

ExcelPlast Tunisie is a Tunisian company whose product portfolio covers PP and polyester plastic sheeting. Organisations of this type typically operate in the plastics and packaging materials sector, supplying industrial and commercial customers with films, sheets, and related products used in packaging, construction, agriculture, and manufacturing processes. Such firms commonly hold commercial contracts, supplier and customer records, production specifications, financial data, and employee information. A breach at a plastics manufacturer can disrupt supply chains, expose proprietary process details, and create secondary risks for partners who rely on the company’s materials. Because the sector often involves cross-border trade and just-in-time delivery, even limited operational disruption can have wider commercial effects. The listing of ExcelPlast Tunisie therefore carries potential consequences beyond the organisation itself, though the precise operational impact remains unconfirmed.

What data was at risk

The public record states that internal files were exfiltrated in a ransomware attack. No further breakdown of file types, databases, or specific categories of personal or commercial data has been disclosed. Organisations in the plastics manufacturing sector typically maintain employee records, customer and supplier contact details, contracts, pricing information, production formulas or process documentation, and financial records. Whether any of these categories were among the internal files claimed by orca is unconfirmed. Exact contents of the alleged exfiltration remain unknown; readers should treat any assertion of specific data types beyond “internal files” as unverified.

What's at stake

For individuals whose information may have been held by ExcelPlast Tunisie—employees, contractors, or business contacts—the primary risks include potential misuse of personal or contact data if it was among the internal files taken. That could lead to targeted phishing, social-engineering attempts, or identity-related fraud. For the organisation, stakes include operational disruption from ransomware encryption, possible regulatory or contractual obligations if personal data was involved, reputational damage from a public listing, and the cost of investigation and recovery. Business partners may face secondary exposure if shared commercial information was compromised. Because the number of people affected and the precise data categories remain unknown, the concrete scale of harm cannot be quantified from public sources alone. The situation underscores the value of monitoring for unusual account activity and of treating unsolicited communications that reference the company with caution.

Were you affected?

If you have a past or present relationship with ExcelPlast Tunisie—as an employee, supplier, customer, or other contact—consider practical steps: monitor financial and email accounts for unexpected activity, enable multi-factor authentication where available, and be alert to phishing that references the company or the incident. Change passwords on any accounts that reused credentials associated with the organisation. Because the full scope of data involved is unconfirmed, these measures are precautionary rather than a response to confirmed personal exposure. Readers can also run a free exposure scan of their email address to check whether their information has already appeared in known breach data sets. Public detail on this incident remains limited; further clarity would depend on official statements from the company or independent verification beyond the group’s listing.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyExcelPlast Tunisie security record
87/100
DoxxScan™ · Low doxx risk
B 80Good record

1 reported incident on record.

See ExcelPlast Tunisie’s full breach history →

More recent breaches

Transtec SAS Listed by orca Ransomware GroupOctober 4, 2024Chernan Technology Listed by orca Ransomware GroupSeptember 18, 2024Casale Del Giglio Listed by orca Ransomware GroupApril 27, 2026Transport Lutztulln Listed by orca Ransomware GroupMay 7, 2025

Latest breaches

Read GalaxyWarden’s full analysis of the ExcelPlast Tunisie Listed by orca Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by orca — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram