LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Pe*************.lk Listed by cloak Ransomware Group

HIGH severityUnverified claimHow we verify

Pe*************.lk Listed by cloak Ransomware Group: Ransomware Claim — What’s Alleged & What To Do

RBRecent Breaches Breach Intelligence·April 18, 2025
Pe*************.lk Listed by cloak Ransomware Group

Reported April 18, 2025.

HIGH
Severity
April 18, 2025
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

Pe*************.lk was listed by the cloak ransomware group on April 18, 2025, after internal files were taken in a ransomware attack. If you have an account or relationship with the organization, review any notices it issues and consider changing passwords or enabling additional security steps.

Severity & verification
HIGH severityUnverified claim
Data types not itemised.
Published on a ransomware group’s leak site — an unverified extortion claim until the named organization or credible reporting corroborates it.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

People whose personal or professional details may sit inside the systems of Pe*************.lk now face the practical question of whether those records have left the organisation’s control. On 18 April 2025 the organisation appeared on a ransomware group’s leak site, and the group claims to have taken internal files. The number of individuals involved remains unknown, so anyone who has dealt with the organisation has reason to treat the listing as a signal worth checking rather than dismissing.

Public information is limited to the claim itself and the description of the material as internal files obtained in a ransomware attack. That scarcity of detail does not reduce the stakes for those who may be affected; it simply means the next steps rest on caution and verification rather than on a complete picture of what was taken.

What happened

Pe*************.lk was listed on the cloak ransomware leak site on or around 18 April 2025. According to the listing, the group claims to have exfiltrated internal files during a ransomware attack. No further technical details—such as the initial access method, the precise date of intrusion, the volume of data, or any ransom demand—have been made public in the available record. The number of people whose information may be involved is listed as unknown. The incident is therefore known only through the group’s claim of theft and the organisation’s appearance on the leak site; independent confirmation of the full scope has not been reported.

Inside cloak

Cloak is a ransomware operation that follows a now-familiar pattern: operators gain access to a network, move laterally, exfiltrate data, and then encrypt systems while threatening to publish the stolen material if payment is not made. Like many contemporary groups, cloak maintains a leak site on which it posts victim names and, in some cases, sample files to pressure organisations. Public reporting on cloak has described the use of double-extortion tactics—combining encryption with the threat of data release—and the targeting of organisations across multiple sectors and regions. These general characteristics are well documented for the group as a whole.

In the present case the only specific claim attached to Pe*************.lk is the listing itself and the assertion that internal data was stolen. No additional statements by cloak about this particular victim, no sample files, and no confirmation of publication beyond the listing have been supplied in the available facts. The listing should therefore be treated as an unverified claim by the group rather than as independently established fact.

Who is Pe*************.lk?

Pe*************.lk is an organisation whose public-facing identity is associated with a .lk domain, indicating a connection to Sri Lanka. Beyond the name and the domain, detailed public background on its exact size, ownership structure, or day-to-day operations is limited in the material provided for this account. Organisations operating under such domains commonly include commercial firms, service providers, or institutions that hold customer, employee, or partner records as part of ordinary business.

A breach claim against any organisation that maintains internal files is consequential because those files frequently contain the operational data needed to run the entity—contracts, correspondence, credentials, financial records, or personal information of staff and clients. Even without a full public profile of Pe*************.lk, the mere fact that internal material is alleged to have left its control raises the possibility that people who interact with the organisation could see their details appear in secondary markets or be used for further fraud. That possibility is what makes the listing material for ordinary people rather than a purely technical event.

What was likely exposed

The available record states that internal files were exfiltrated in a ransomware attack. No more granular inventory—such as specific document types, databases, or categories of personal data—has been disclosed. Organisations of this general kind typically hold a range of internal material that can include employee records, client or customer information, financial documents, operational correspondence, and system credentials. Whether any or all of those categories were present in the material claimed by cloak remains unconfirmed.

Until more precise information surfaces, the prudent working assumption is simply that internal organisational material left the environment and that anyone with a relationship to Pe*************.lk should consider the possibility that their details were among it.

The real-world impact

For individuals, the concrete risks are the ordinary ones that follow any unauthorised release of internal files: phishing or social-engineering attempts that reference real organisational details, attempts to reuse credentials if any were present, and the longer-term possibility that personal information could be sold or traded. Because the scale is unknown, it is impossible to say how many people face elevated risk; the absence of a number does not eliminate the risk for those who are affected.

For the organisation itself, the impact includes the operational disruption that typically accompanies ransomware, the potential regulatory and contractual obligations that arise when internal data leaves controlled systems, and the reputational cost of a public leak-site listing. None of these consequences has been quantified in the available record, and no statement of confirmed financial loss or confirmed data publication beyond the listing itself has been supplied. The practical effect is therefore best understood as an unresolved exposure that both the organisation and any associated individuals must manage with incomplete information.

Were you affected?

If you have had any dealings with Pe*************.lk—as a customer, employee, partner, or supplier—treat the claim as a reason to take basic protective steps. Change passwords that may have been used in connection with the organisation, enable multi-factor authentication wherever it is available, and watch for unexpected messages that appear to come from the organisation or that reference its internal processes. Monitor financial accounts for unusual activity and be cautious about sharing additional personal information in response to unsolicited contact.

Because the full contents of the claimed exfiltration remain unconfirmed, the most direct way for an individual to check whether their own email address has already appeared in known breach data is to run a free exposure scan. Such a scan will not prove or disprove involvement in this specific incident, but it will show whether the address has surfaced elsewhere and can serve as an early indicator that further vigilance is warranted. Keep records of any suspicious contact and report clear fraud to the appropriate local authorities. Public detail on this incident remains limited; measured caution is the proportionate response.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

Attributed to

Method

CompanyPe*************.lk security record
87/100
DoxxScan™ · Low doxx risk
B 80Good record

1 reported incident on record.

See Pe*************.lk’s full breach history →

More recent breaches

*****l*****.us Listed by cloak Ransomware GroupDecember 19, 2025****e-det**.de Listed by cloak Ransomware GroupNovember 18, 2025Con*******.com Listed by cloak Ransomware GroupNovember 18, 2025*****.com Listed by cloak Ransomware GroupOctober 16, 2025

Latest breaches

Read GalaxyWarden’s full analysis of the Pe*************.lk Listed by cloak Ransomware Group →

Source: threat-actor leak-site listing

Publicly posted by cloak — unverified claim, pending independent verification

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram