Naftor and Grupa Pern (Naftoport/ SIARKOPOL/ SARMATIA/ NAFTOSERWIS) is the most dangerous Listed by alphv Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The Naftor and Grupa Pern (Naftoport/ SIARKOPOL/ SARMATIA/ NAFTOSERWIS) is the most dangerous Listed by alphv Ransomware Group (reported November 14, 2023) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
On 14 November 2023, the ransomware group known as alphv publicly listed Naftor and entities associated with Grupa PERN—including references to Naftoport, SIARKOPOL, SARMATIA and NAFTOSERWIS—on its leak site. The group claimed that internal files had been exfiltrated in a ransomware attack and issued a lengthy warning directed at clients and partners. The number of people affected remains unknown, and independent confirmation of the full scope of the incident has not been established in the available record.
The listing matters because these organisations operate in critical energy and logistics infrastructure in Poland. Any confirmed exposure of internal business material could affect commercial partners, contractors and individuals whose details appear in corporate systems. At present, the public picture rests largely on the threat actor’s own statements.
What happened
According to the alphv listing dated 14 November 2023, the group asserted that it had conducted a ransomware attack against Naftor Sp. z o.o. and related Grupa PERN companies and had exfiltrated internal files. The post carried an aggressive warning claiming that cooperation with Naftor and Grupa PERN “may result in the leakage of your data,” that the companies “do not comply with the laws of the European Union and in particular the GDPR,” and that clients and partners should “urgently terminate their contracts” because “all confidential documents will be made public in the near future.” The group further claimed that vulnerabilities had already been used to penetrate the networks of partners and clients.
No independent verification of the intrusion method, the precise date of any intrusion, the volume of data taken, or the identities of any secondary victims has been supplied in the available facts. The number of individuals whose personal information may be involved is recorded as unknown. Public detail beyond the group’s leak-site claims is therefore limited.
Inside alphv
Alphv, also widely known as BlackCat, is a ransomware operation that emerged in late 2021 and has operated on a ransomware-as-a-service model. Affiliates typically gain initial access, move laterally, exfiltrate data, and then deploy encryption while threatening to publish stolen material on a dedicated leak site if a ransom is not paid. The group has been linked to numerous attacks on organisations across multiple sectors and jurisdictions. It has used double-extortion tactics—combining encryption with the threat of data publication—and has at times posted lengthy, sometimes sensational statements intended to pressure victims and their business partners.
In this case, the leak-site entry itself constitutes an unverified claim by the group. Nothing in the provided record confirms that alphv’s specific assertions about GDPR non-compliance, secondary network compromises, or imminent wholesale publication of every confidential document have been independently validated. Such claims should be treated as the actor’s statements rather than established fact.
About Naftor and Grupa Pern (Naftoport/ SIARKOPOL/ SARMATIA/ NAFTOSERWIS) is the most dangerous Listed by alphv Ransomware Group
Naftor Sp. z o.o. and the broader Grupa PERN constellation operate in Poland’s fuel logistics, storage and related industrial sectors. PERN is a major player in the storage and transport of crude oil and fuels; associated names such as Naftoport (a key Baltic oil terminal), Siarkopol, Sarmatia and Naftoserwis reflect activities spanning terminal operations, sulphur and chemical handling, pipeline or transit projects, and technical services. Organisations of this type routinely manage commercially sensitive contracts, operational data, employee records, supplier and customer information, and technical documentation tied to critical energy infrastructure.
A breach affecting such entities is consequential because the sector sits at the intersection of national energy security, industrial supply chains and cross-border logistics. Even limited exposure of internal files can create commercial, contractual and regulatory complications for the companies themselves and for the many third parties that interact with them.
The information in question
The only data type explicitly named in the available record is “internal files exfiltrated in ransomware attack.” No further breakdown—such as whether the material includes personal data of employees or customers, financial records, technical schematics, or partner contracts—has been disclosed in the facts provided. The alphv statement asserts that confidential documents will be made public and that partner and client networks may already have been reached, but these remain the group’s claims.
Organisations in fuel logistics and industrial services typically hold employee personal data, contractor and supplier details, commercial agreements, operational logs and sometimes regulated infrastructure information. Whether any of those categories were in fact taken, and in what volume, is unconfirmed. Readers should not assume specific data types may have been exposed beyond the general description of internal files.
What's at stake
For individuals, the practical risk depends on whether personal information was among the internal files. If names, contact details, identification numbers or employment records were included, affected people could face phishing, social-engineering attempts or other misuse of that information. Because the number of people affected is unknown and the exact contents are unconfirmed, the individual impact cannot yet be quantified.
For the organisations and their partners, stakes include potential contractual disputes, regulatory scrutiny under European data-protection rules, reputational harm, and the operational cost of investigating and containing any intrusion. The threat actor’s public call for clients to terminate contracts is itself a form of pressure that can disrupt ordinary business relationships even before any files are published. Secondary risk to partners arises only if the group’s claim of further network penetration proves accurate—an assertion that remains unverified in the public record.
If your data was in this claimed breach
If you have a past or present relationship with Naftor, Grupa PERN or the named associated entities, treat the situation cautiously until more verified information appears. Monitor financial and email accounts for unusual activity, be alert to unexpected messages that reference the companies or urgent contract matters, and consider placing fraud alerts where appropriate. If you are a business partner, review access controls and any shared credentials or systems that connected to the affected organisations.
You can also run a free exposure scan of your email address to check whether your information has already surfaced in known breach data sets. That step will not confirm or deny involvement in this specific incident, but it can indicate whether your details appear in other publicly circulating collections and help you prioritise further protective measures.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
ende.co.ao is a company you can test corporate network hack on and have 100% hacking succe Listed by alphv Ransomware GroupFreeport-McMoran - NYSE: FCX Listed by alphv Ransomware GroupMammoth Energy (NASDAQ: TUSK) Listed by alphv Ransomware GroupBadan Operasi Bersama Pt Bumi Siak Pusako Pertamina Hulu Listed by alphv Ransomware GroupLatest breaches
Publicly posted by alphv — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.